Input validation vulnerability in Gwolle Guestbook 2.1.0

The Gwolle Guestbook plugin for WordPress is not secure for versions up to 2.1.0. Attackers who are not authenticated can exploit this security flaw by tricking a website administrator into clicking on a link. This link will then allow the attacker to approve entries that were previously denied. This is because the security feature known as ‘wp-nonce’ is either missing or not working properly.

Detected in:

Gwolle Guestbook fixed vulnerable versions: >= * <= 2.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.