The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE ID: CVE-2023-0992
CVSS Base Severity: HIGH
CVSS Base Score: 7.2
Vendor: paultgoodchild
Product: Shield Security – Smart Bot Blocking & Intrusion Prevention
EPSS Score: 0.11% (probability of being exploited)
EPSS Percentile: 46.05% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)