Input validation vulnerability in WPB Show Core 2.2

The WPB Show Core plugin for WordPress has a security issue in all versions up to 2.2. An unauthenticated attacker can use the ‘path’ parameter to make requests to external web locations from the web application. This can be used to look at and manipulate information from internal services.

Detected in:

WPB Show Core fixed vulnerable versions: >= * <= 2.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.