WordPress Plugin Vulnerabilities

WPB Show Core <= 2.2 - Unauthenticated Local File Inclusion

Description

This plugin is vulnerable to a local file inclusion via the `path` parameter.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
LFI
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Mohamed Abdelhady
Submitter
Mohamed Abdelhady
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2023-11-06 (about 2 years ago)
Added
2023-11-06 (about 2 years ago)
Last Updated
2023-11-06 (about 2 years ago)

Other