Shield Security WP Plugin: Patched Serious Vulnerability Secured

February 11, 2024
1 min read

A serious security vulnerability has been discovered in the Shield Security WP plugin, which could allow arbitrary file inclusion. The flaw has been patched by the developers with the latest plugin release, and users are urged to update to the latest version as soon as possible. The vulnerability specifically affected the plugin’s render_action_template parameter, allowing an unauthenticated attacker to include malicious PHP files on the target server and execute malicious PHP code. The vulnerability received a critical security rating with a CVSS score of 9.8. The issue typically affected PHP files only, ruling out the possibility of remote code execution attacks. The plugin developers have released version 18.5.10 to patch the vulnerability, but users are advised to update to the latest available version.

Latest from Blog

Top 20 Linux Admin Tools for 2024

TLDR: Top Linux Admin Tools in 2024 Key points: Linux admin tools streamline system configurations, performance monitoring, and security management. Popular Linux admin tools include Webmin, Puppet, Zabbix, Nagios, and Ansible. Summary

Bogus job tempts aerospace, energy workers

TLDR: A North Korean cyberespionage group is posing as job recruiters to target employees in aerospace and energy sectors. Mandiant reports that the group uses fake job descriptions stored in malicious archives