Input validation vulnerability in Gwolle Guestbook 4.1.2

The Gwolle Guestbook plugin for WordPress had an issue in versions before 4.2.0 that allowed malicious code to be inserted and reflected back on an admin page. This was possible because the plugin did not properly filter and protect the gwolle_gb_user_email parameter.

Detected in:

Gwolle Guestbook fixed vulnerable versions: >= * <= 4.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.