Vulnerability Description
The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scripting
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpb Show Core Project | Wpb Show Core | < 2.7 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/d7034ac2-0098-48d2-9ba9-87e09b178f7d/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/d7034ac2-0098-48d2-9ba9-87e09b178f7d/ExploitThird Party Advisory
FAQ
What is CVE-2024-1956?
CVE-2024-1956 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading to a Reflected Cross-Site Scr...
How severe is CVE-2024-1956?
CVE-2024-1956 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-1956?
Check the references section above for vendor advisories and patch information. Affected products include: Wpb Show Core Project Wpb Show Core.