← Back

Wpb Show Core Project

wpb_show_core_project

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Wpb Show Core
wpb_show_core

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpb Show Core Project
1Wpb Show Core
May 19, 2025
Apr 8, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users s...Show more
The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin or unauthenticated usersShow less
1Wpb Show Core Project
1Wpb Show Core
May 19, 2025
Apr 8, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting
1Wpb Show Core Project
1Wpb Show Core
May 19, 2025
Apr 8, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege u...Show more
The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as adminShow less
1Wpb Show Core Project
1Wpb Show Core
Nov 21, 2024
Nov 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.
1Wpb Show Core Project
1Wpb Show Core
Nov 21, 2024
Nov 27, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter.
1Wpb Show Core Project
1Wpb Show Core
Apr 30, 2025
Nov 14, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The WPB Show Core WordPress plugin does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.