The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `MfaEmailDisable` action in all versions up to, and including, 21.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable the global Email 2FA setting for the entire site.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paultgoodchild
Paultgoodchild shield: Blocks Bots, Protects Users, And Prevents Security Breaches Wordpress Wordpress wordpress |
|
| Vendors & Products |
Paultgoodchild
Paultgoodchild shield: Blocks Bots, Protects Users, And Prevents Security Breaches Wordpress Wordpress wordpress |
Thu, 19 Feb 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `MfaEmailDisable` action in all versions up to, and including, 21.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable the global Email 2FA setting for the entire site. | |
| Title | Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches <= 21.0.9 - Missing Authorization to Authenticated (Subscriber+) Email MFA Update | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-19T04:36:19.188Z
Reserved: 2025-12-10T02:33:33.560Z
Link: CVE-2025-14427
No data.
Status : Awaiting Analysis
Published: 2026-02-19T07:17:35.263
Modified: 2026-02-19T15:53:02.850
Link: CVE-2025-14427
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:07:02Z
Weaknesses