Getshieldsecurity maintains a narrowly focused WordPress security plugin portfolio, where its Shield Security product addresses access control and input handling for WordPress installations. The vendor's disclosed vulnerabilities skew toward serious outcomes and frequently acquire public exploit code, concentrating through weakness classes including cross-site scripting, PHP remote file inclusion, path traversal, and missing authorization that are characteristic of web-application and plugin-layer risks. Defenders should prioritize patching this plugin across WordPress deployments and monitor for exploitation activity; live severity and exploit-availability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getshieldsecurity over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6989CRITICAL The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via | Feb 5, 2024 | 9.8 | 71 | NO | YES |
CVE-2023-0992MEDIUM The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible | Jun 9, 2023 | 6.1 | 70 | NO | NO |
CVE-2024-7313MEDIUM The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting whic | Aug 26, 2024 | 6.1 | 27 | NO | YES |
CVE-2024-22163MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shield Security Shield Security – Smart Bot Blocking & Intrusion Prevention Se | Jan 31, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-0993MEDIUM The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action in versions up to, and including, 17.0.17. This allows authen | Jun 9, 2023 | 4.3 | 17 | NO | NO |
CVE-2022-0211MEDIUM The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even whe | Feb 21, 2022 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getshieldsecurity.
Media articles that mention a CVE ID that affects a product developed by Getshieldsecurity — matched by CVE ID, not by vendor name.