CVE-2026-0722 PUBLISHED

Shield Security <= 21.0.8 - Cross-Site Request Forgery to SQL Injection

Assigner: Wordfence
Reserved: 08.01.2026 Published: 19.02.2026 Updated: 19.02.2026

The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired' function. This makes it possible for unauthenticated attackers to execute SQL injection attacks, extracting sensitive information from the database, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor paultgoodchild
Product Shield: Blocks Bots, Protects Users, and Prevents Security Breaches
Versions Default: unaffected
  • affected from * to 21.0.8 (incl.)

Credits

  • Dmitrii Ignatyev finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE