VYPR

Gwolle Guestbook

by WordPress

CVEs (2)

  • CVE-2015-8351CriSep 11, 2017
    risk 0.64cvss 9.0epss 0.37

    PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE:…

  • CVE-2018-17884MedOct 2, 2018
    risk 0.40cvss 6.1epss 0.01

    XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php