PT-2023-32453 · WordPress · Wpb Show Core

Mohamed Abdelhady

·

Published

2023-11-27

·

Updated

2023-12-01

·

CVE-2023-5974

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPB Show Core WordPress plugin versions through 2.2
Description The issue concerns server-side request forgery (SSRF) via the path parameter. This allows for potentially malicious requests to be made to the server.
Recommendations For WPB Show Core WordPress plugin versions through 2.2, update to a version that fixes this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the path parameter to minimize the risk of exploitation.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2023-5974

Affected Products

Wpb Show Core