PT-2023-31118 · WordPress · Wpb Show Core

Mohamed Abdelhady

·

Published

2023-11-27

·

Updated

2023-12-01

·

CVE-2023-4922

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPB Show Core WordPress plugin versions through 2.2
Description The issue concerns a local file inclusion vulnerability via the path parameter. This allows for potential unauthorized access to sensitive files on the system.
Recommendations For WPB Show Core WordPress plugin versions through 2.2, update to a version that fixes this issue, as using the path parameter can lead to local file inclusion. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2023-4922

Affected Products

Wpb Show Core