Gwolle Guestbook <= 4.9.2 - Unauthenticated Stored Cross-Site Scripting via `gwolle_gb_content` Parameter
medium
The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ parameter in all versions up to, and including, 4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 4.9.2
- Fixed in:
- 4.9.3
- Disclosed:
- Jul 9, 2025
CVE-2025-5807 on NVD →
Gwolle Guestbook <= 4.7.1 - Reflected Cross-Site Scripting
medium
The Gwolle Guestbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...
- CVSS:
- 6.1
- Affected:
- up to 4.7.1
- Fixed in:
- 4.7.2
- Disclosed:
- Jan 31, 2025
CVE-2025-24710 on NVD →
Gwolle Guestbook <= 4.1.2 - Reflected Cross-Site Scripting
medium
The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page
- CVSS:
- 6.1
- Affected:
- up to 4.1.2
- Fixed in:
- 4.2
- Disclosed:
- Nov 23, 2021
CVE-2021-24980 on NVD →
Gwolle Guestbook <= 2.5.3 - Cross-Site Scripting
medium
XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php
- CVSS:
- 6.1
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Jul 28, 2018
CVE-2018-17884 on NVD →
Gwolle Guestbook <= 2.1.0 - Cross-Site Request Forgery
high
The Gwolle Guestbook plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the wp-nonces. This makes it possible for unauthenticated attackers to mass approve denied entries via a forged request granted they can...
- CVSS:
- 8.8
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Mar 1, 2017
Gwolle Guestbook <= 2.1.0 - Stored Cross-Site Scripting
medium
The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘/gwolle-gb/admin/page-editor.php’ file in versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- CVSS:
- 6.1
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Mar 1, 2017
Gwolle Guestbook <= 1.5.3 - Remote File Inclusion
critical
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and...
- CVSS:
- 9
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- Nov 4, 2015
CVE-2015-8351 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database