plugin

Gwolle Gb Vulnerabilities

7 known security issues reported for the Gwolle Gb WordPress plugin. Most recent disclosed Jul 9, 2025.

1 critical 1 high 5 medium

Running Gwolle Gb on your site? Check whether your installed version is affected.

Scan your site free

Gwolle Guestbook <= 4.9.2 - Unauthenticated Stored Cross-Site Scripting via `gwolle_gb_content` Parameter

medium

The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ parameter in all versions up to, and including, 4.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...

CVSS:
6.1
Affected:
up to 4.9.2
Fixed in:
4.9.3
Disclosed:
Jul 9, 2025

CVE-2025-5807 on NVD →

Gwolle Guestbook <= 4.7.1 - Reflected Cross-Site Scripting

medium

The Gwolle Guestbook plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfull...

CVSS:
6.1
Affected:
up to 4.7.1
Fixed in:
4.7.2
Disclosed:
Jan 31, 2025

CVE-2025-24710 on NVD →

Gwolle Guestbook <= 4.1.2 - Reflected Cross-Site Scripting

medium

The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page

CVSS:
6.1
Affected:
up to 4.1.2
Fixed in:
4.2
Disclosed:
Nov 23, 2021

CVE-2021-24980 on NVD →

Gwolle Guestbook <= 2.5.3 - Cross-Site Scripting

medium

XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php

CVSS:
6.1
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
Jul 28, 2018

CVE-2018-17884 on NVD →

Gwolle Guestbook <= 2.1.0 - Cross-Site Request Forgery

high

The Gwolle Guestbook plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.1.0. This is due to missing or incorrect nonce validation on the wp-nonces. This makes it possible for unauthenticated attackers to mass approve denied entries via a forged request granted they can...

CVSS:
8.8
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Mar 1, 2017

Gwolle Guestbook <= 2.1.0 - Stored Cross-Site Scripting

medium

The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘/gwolle-gb/admin/page-editor.php’ file in versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Mar 1, 2017

Gwolle Guestbook <= 1.5.3 - Remote File Inclusion

critical

PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and...

CVSS:
9
Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Nov 4, 2015

CVE-2015-8351 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database