WordPress WPB Show Core 漏洞列表
共找到 4 个与 WordPress WPB Show Core 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2022-3484: WordPress WPB Show Core - Cross-Site Scripting POC
WordPress wpb-show-core plugin through TODO contains a cross-site scripting vulnerability. The plugin does not sanitize and escape a parameter before outputting it back in the page. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2023-5974: WordPress WPB Show Core <= 2.2 - Server-Side Request Forgery POC
The WPB Show Core WordPress plugin through version 2.2 is vulnerable to Server-Side Request Forgery (SSRF) via the 'path' parameter in the download-file.php script. This vulnerability allows unauthenticated attackers to make the server perform requests to arbitrary URLs. -
CVE-2022-3484: WordPress WPB Show Core - Cross-Site Scripting POC
WordPress wpb-show-core plugin through TODO contains a cross-site scripting vulnerability. The plugin does not sanitize and escape a parameter before outputting it back in the page. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. -
CVE-2023-5974: WordPress WPB Show Core <= 2.2 - Server-Side Request Forgery POC
The WPB Show Core WordPress plugin through version 2.2 is vulnerable to Server-Side Request Forgery (SSRF) via the 'path' parameter in the download-file.php script. This vulnerability allows unauthenticated attackers to make the server perform requests to arbitrary URLs.