Cross-Site Scripting Vulnerability in Gwolle Guestbook Plugin for WordPress
CVE-2018-17884
6.1MEDIUM
What is CVE-2018-17884?
A Cross-Site Scripting (XSS) vulnerability exists in the Gwolle Guestbook plugin for WordPress, specifically within the admin/gb-dashboard-widget.php file. This vulnerability can be exploited via the PATH_INFO parameter when accessed through wp-admin/index.php. As a result, attackers may execute arbitrary JavaScript code in the context of an authenticated user's session. Users are advised to update to version 2.5.4 or later to mitigate the risk.