Lucene search

K
wpvulndbJrXnmWPVDB-ID:E50BCB39-9A01-433F-81B3-FD4018672B85
HistoryNov 23, 2021 - 12:00 a.m.

Gwolle Guestbook < 4.2.0 - Reflected Cross-Site Scripting

2021-11-2300:00:00
JrXnm
wpscan.com
7
gwolle guestbook
cross-site scripting
reflected
admin page

EPSS

0.001

Percentile

43.7%

The plugin does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page

PoC

EPSS

0.001

Percentile

43.7%

Related for WPVDB-ID:E50BCB39-9A01-433F-81B3-FD4018672B85