Impact
The Gwolle Guestbook plugin for WordPress contains a stored cross‑site scripting flaw in the gwolle_gb_content parameter. Because the input is stored without proper sanitisation or escaping, content that includes malicious JavaScript can be saved and later rendered within guestbook entries. When a user views a page that contains the injected content, the browser executes the stored script.
Affected Systems
The vulnerability affects all versions of the Gwolle Guestbook plugin up to and including 4.9.2 on WordPress sites.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate level of severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can inject the malicious script via the gwolle_gb_content field in an unauthenticated form submission, which then persists and is served to subsequent visitors.
OpenCVE Enrichment
EUVD