Lucene search

K
patchstackHigh-Tech Bridge SAPATCHSTACK:611E646DBAC24E39E13EE452F27DA6A6
HistoryDec 03, 2015 - 12:00 a.m.

WordPress Gwolle Guestbook Plugin 1.5.3 - Remote File Inclusion

2015-12-0300:00:00
High-Tech Bridge SA
patchstack.com
6

This Gwolle Guestbook plugin is prone to remote file include vulnerability. It allows an attacker to include a remote file and get access to the server, because "abspath"parameter is not sanitized before it will be using in PHP require() function and “wp-load.php” file is included on the web server.

Solution

           Upgrade the plugin.