VendorsGwolle Guestbook Projectgwolle_guestbookall versions
Vulnerabilities

Gwolle Guestbook Project Gwolle Guestbook

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2015-8351
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled.
Published 2017-09-11 · Modified
9.01 PoCEPSS 0.370
CVE-2018-17884
XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php
Published 2018-10-02 · Modified
6.1EPSS 0.012
CVE-2021-24980
Gwolle Guestbook < 4.2.0 - Reflected Cross-Site Scripting
Published 2021-12-27 · Modified
6.1EPSS 0.008
CVE-2017-20089
Gwolle Guestbook Plugin cross site scriting
Published 2022-06-23 · Modified
6.1EPSS 0.007