CVE-2021-24980
MEDIUM WAF: High
CVSS 6.1
Published: 2021-12-27
CWE-79
The Gwolle Guestbook WordPress plugin before 4.2.0 does not sanitise and escape the gwolle_gb_user_email parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue in an admin page
WAF Coverage Analysis
Cross-Site Scripting (XSS)
High WAF Coverage
OWASP: A03:2021 Injection
941xxx - XSS / XXE
Affected Software
| Vendor | Product | Version |
|---|---|---|
| gwolle_guestbook_project | gwolle_guestbook | up to 4.2.0 |
References
- wpscan.com (Exploit, Third Party Advisory)