VYPR

Security Shield 2010

by WordPress

CVEs (3)

  • CVE-2026-0722MedFeb 19, 2026
    risk 0.42cvss 6.5epss 0.00

    The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired' function. This makes…

  • CVE-2026-0561MedFeb 19, 2026
    risk 0.40cvss 6.1epss 0.00

    The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 21.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2025-14427MedFeb 19, 2026
    risk 0.28cvss 4.3epss 0.00

    The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `MfaEmailDisable` action in all versions up to, and including, 21.0.9. This makes it…