The Wpb Show Core Project maintains a WordPress plugin focused on content presentation that, despite a narrow scope, operates across a potentially large installed base of WordPress sites. Vulnerabilities affecting this plugin skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with the exposure recalling repeatedly through web-layer weakness classes including cross-site scripting and server-side request forgery that are inherent to user-facing WordPress extensions. Defenders should treat this plugin's advisories as high-priority for any affected WordPress instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpb Show Core Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-5974CRITICAL The WPB Show Core WordPress plugin through 2.2 is vulnerable to server-side request forgery (SSRF) via the `path` parameter. | Nov 27, 2023 | 9.8 | 35 | NO | YES |
CVE-2023-4922CRITICAL The WPB Show Core WordPress plugin through 2.2 is vulnerable to a local file inclusion via the `path` parameter. | Nov 27, 2023 | 9.8 | 33 | NO | NO |
CVE-2022-3484MEDIUM The WPB Show Core WordPress plugin does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting. | Nov 14, 2022 | 6.1 | 31 | NO | YES |
CVE-2024-1956MEDIUM The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Refl | Apr 8, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-1958MEDIUM The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which coul | Apr 8, 2024 | 4.8 | 16 | NO | NO |
CVE-2024-1292MEDIUM The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting whic | Apr 8, 2024 | 4.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpb Show Core Project.
Media articles that mention a CVE ID that affects a product developed by Wpb Show Core Project — matched by CVE ID, not by vendor name.