Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-103362
HistoryDec 28, 2021 - 12:00 a.m.

WordPress Gwolle Guestbook Plugin Cross-Site Scripting Vulnerability (CNVD-2021-103362)

2021-12-2800:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
wordpress
gwolle guestbook
cross-site scripting
vulnerability
php
mysql
user-supplied data
validation filtering
client-side javascript

EPSS

0.001

Percentile

43.7%

WordPress is the Wordpress Foundation’s suite of blogging platforms developed using the PHP language. The platform supports personal blogging sites on PHP and MySQL servers.The WordPress Gwolle Guestbook plugin has a cross-site scripting vulnerability in versions prior to 4.2.0, which stems from the plugin’s lack of user-supplied data and output data validation filtering in the gwolle_gb_user_email parameter. An attacker could use this vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

43.7%