VendorsGwolle Guestbook Projectgwolle_guestbookany version
Vulnerabilities

Gwolle Guestbook Project Gwolle Guestbook any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2015-8351
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled.
Published 2017-09-11 · Modified
9.01 PoCEPSS 0.370
CVE-2018-17884
XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php
Published 2018-10-02 · Modified
6.1EPSS 0.012
CVE-2021-24980
Gwolle Guestbook < 4.2.0 - Reflected Cross-Site Scripting
Published 2021-12-27 · Modified
6.1EPSS 0.008