Plugin Vulnerability Hub
Plugin 11 known issues Latest disclosed Feb 18, 2026

Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Vulnerabilities

Review known vulnerability records for the WordPress plugin Shield: Blocks Bots, Protects Users, and Prevents Security Breaches (`wp-simple-firewall`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-0722, CVE-2026-0561 and CVE-2025-14427, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
11
High or Critical
3
Patch Coverage
100%
Last Updated
Feb 19, 2026
Priority CVE Quick Links

Fast paths into Shield: Blocks Bots, Protects Users, and Prevents Security Breaches CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
11
CVE-2023-6989 Critical 18.5.10
CVE-2023-6989 Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Local File Inclusion

Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion

CVE-2024-22163 High 18.5.8
CVE-2024-22163 Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Stored Cross-Site Scripting

Shield Security <= 18.5.7 - Unauthenticated Stored Cross-Site Scripting via getColumnContent_Page

CVE-2023-0992 High 17.0.18
CVE-2023-0992 Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Stored Cross-Site Scripting

Shield Security <= 17.0.17 - Unauthenticated Stored Cross-Site Scripting

CVE-2026-0722 Medium 21.0.10
CVE-2026-0722 Shield: Blocks Bots, Protects Users, and Prevents Security Breaches SQL Injection

Shield Security <= 21.0.8 - Cross-Site Request Forgery to SQL Injection

CVE-2026-0561 Medium 21.0.10
CVE-2026-0561 Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Cross-Site Scripting

Shield Security <= 21.0.8 - Unauthenticated Reflected Cross-Site Scripting via 'message' Parameter

CVE-2024-7313 Medium 20.0.6
CVE-2024-7313 Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Cross-Site Scripting

Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 20.0.5 - Reflected Cross-Site Scripting

CVE-2022-0211 Medium 13.0.6
CVE-2022-0211 Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Stored Cross-Site Scripting

Shield Security <= 13.0.5 - Admin+ Stored Cross-Site Scripting

CVE-2025-14427 Medium 21.0.10
CVE-2025-14427 Shield: Blocks Bots, Protects Users, and Prevents Security Breaches Vulnerability

Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches <= 21.0.9 - Missing Authorization to Authenticated (Subscriber+) Email MFA Update

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Shield: Blocks Bots, Protects Users, and Prevents Security Breaches so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
11 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 2 high severity findings.
Recent CVEs
CVE-2026-0722, CVE-2026-0561 and CVE-2025-14427
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Shield: Blocks Bots, Protects Users, and Prevents Security Breaches

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-0722
CVE-2026-0722: Shield Security <= 21.0.8 - Cross-Site Request Forgery to SQL Injection

The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired' function. This makes...

Published
Feb 18, 2026
Patched Release
21.0.10
Affected Versions
Versions up to 21.0.8
Next Step
Update to 21.0.10 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-0561
CVE-2026-0561: Shield Security <= 21.0.8 - Unauthenticated Reflected Cross-Site Scripting via 'message' Parameter

The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 21.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in...

Published
Feb 18, 2026
Patched Release
21.0.10
Affected Versions
Versions up to 21.0.8
Next Step
Update to 21.0.10 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14427
CVE-2025-14427: Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches <= 21.0.9 - Missing Authorization to Authenticated (Subscriber+) Email MFA Update

The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `MfaEmailDisable` action in all versions up to, and including, 21.0.9. This makes it p...

Published
Feb 18, 2026
Patched Release
21.0.10
Affected Versions
Versions up to 21.0.9
Next Step
Update to 21.0.10 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-15370
CVE-2025-15370: Shield Security <= 21.0.9 - Authenticated (Subscriber+) Insecure Direct Object Reference to Disable Google Authenticator

The Shield: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 21.0.9 via the MfaGoogleAuthToggle class due to missing validation on a user controlled key. This m...

Published
Jan 15, 2026
Patched Release
21.0.10
Affected Versions
Versions up to 21.0.9
Next Step
Update to 21.0.10 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-7313
CVE-2024-7313: Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 20.0.5 - Reflected Cross-Site Scripting

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nav_sub' parameter in all versions up to, and including, 20.0.5 due to insufficient input sanitization and output escaping. This...

Published
Aug 05, 2024
Patched Release
20.0.6
Affected Versions
Versions up to 20.0.5
Next Step
Update to 20.0.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-4344
CVE-2024-4344: Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 19.1.13 - Cross-Site Request Forgery

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 19.1.13. This is due to missing or incorrect nonce validation on the exec function. This makes it possib...

Published
Jun 01, 2024
Patched Release
19.1.11
Affected Versions
Versions up to 19.1.10
Next Step
Update to 19.1.11 or newer if supported.
Plugin Critical Patched: Yes CVE-2023-6989
CVE-2023-6989: Shield Security – Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated attacker to includ...

Published
Feb 05, 2024
Patched Release
18.5.10
Affected Versions
Versions up to 18.5.9
Next Step
Update to 18.5.10 or newer if supported.
Plugin High Patched: Yes CVE-2024-22163
CVE-2024-22163: Shield Security <= 18.5.7 - Unauthenticated Stored Cross-Site Scripting via getColumnContent_Page

The Shield Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the getColumnContent_Page function in versions up to, and including, 18.5.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers t...

Published
Jan 16, 2024
Patched Release
18.5.8
Affected Versions
Versions up to 18.5.7
Next Step
Update to 18.5.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-0993
CVE-2023-0993: Shield Security <= 17.0.17 - Missing Authorization

The Shield Security plugin for WordPress is vulnerable to Missing Authorization on the 'theme-plugin-file' AJAX action in versions up to, and including, 17.0.17. This allows authenticated attackers to add arbitrary audit log entries indicating that a theme or plugin has been edit...

Published
Apr 25, 2023
Patched Release
17.0.18
Affected Versions
Versions before 17.0.18
Next Step
Update to 17.0.18 or newer if supported.
Plugin High Patched: Yes CVE-2023-0992
CVE-2023-0992: Shield Security <= 17.0.17 - Unauthenticated Stored Cross-Site Scripting

The Shield Security plugin for WordPress is vulnerable to stored Cross-Site Scripting in versions up to, and including, 17.0.17 via the 'User-Agent' header. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a...

Published
Apr 25, 2023
Patched Release
17.0.18
Affected Versions
Versions before 17.0.18
Next Step
Update to 17.0.18 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-0211
CVE-2022-0211: Shield Security <= 13.0.5 - Admin+ Stored Cross-Site Scripting

The Shield Security WordPress plugin before 13.0.6 does not sanitise and escape admin notes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.

Published
Jan 19, 2022
Patched Release
13.0.6
Affected Versions
Versions up to 13.0.5
Next Step
Update to 13.0.6 or newer if supported.