Record summary

CVE-2023-5974 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 21, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

wpb-show-core

Default status: affected

CVE ListThrough 2.2affected

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress WPB Show Core <= 2.2 - Server-Side Request ForgeryCVSS 9.8

The WPB Show Core WordPress plugin through version 2.2 is vulnerable to Server-Side Request Forgery (SSRF) via the 'path' parameter in the download-file.php script. This vulnerability allows unauthenticated attackers to make the server perform requests to arbitrary URLs.

Impact

Unauthenticated attackers can perform SSRF attacks via the path parameter, potentially accessing internal resources or scanning internal networks.

Remediation

Update WPB Show Core plugin to a version newer than 2.2.

WeaknessesCWE-918
Authorsritikchaddha
Template tagscvecve2023wpwordpresswp-pluginssrfwpb-show-coreoastvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wpb_show_core_project:wpb_show_core:*:*:*:*:*:wordpress:*:*
FOFA: body="wp-content/plugins/wpb-show-core/"

Source: ProjectDiscovery

References

2