WordPress Plugin Vulnerabilities

WPB Show Core <= 2.2 - Unauthenticated Server Side Request Forgery

Description

This plugin is vulnerable to server-side request forgery (SSRF) via the `path` parameter.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
SSRF
OWASP top 10
CWE

Miscellaneous

Original Researcher
Mohamed Abdelhady
Submitter
Mohamed Abdelhady
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2023-11-06 (about 2 years ago)
Added
2023-11-06 (about 2 years ago)
Last Updated
2023-11-06 (about 2 years ago)

Other