Beta

Report

Gwolle Guestbook <= 4.1.2 is vulnerable to Reflected Cross-Site Scripting (XSS) vulnerability

Unauthenticated
Published
2021-11-22

The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page

CVSS

Score:4.7

Severity:Medium

Version: 4.1.2

There is a patch available in v4.2.0 and we strongly recommend you update to this version as soon as possible.