WP-ViperGB
WP-ViperGB has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2024; all 3 are fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Cross-Site Request Forgery (CSRF).
Every one of the 3 issues recorded for WP-ViperGB has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. WP-ViperGB is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
CVE-2015-9356Viper GuestBook <= 1.3.15 - Cross-Site Scripting
Read the full analysisVulnerability Records
WP-ViperGB
Author
JK
WP-ViperGB is a WordPress plugin designed to replicate the appearance and behavior of the discontinued Viper Guestbook project. It makes it easy to add a stylish and user-friendly guestbook to your blog. Features: Create user-friendly guestbooks without writing a single line of code. Lives in a standard WordPress page and uses comments for entries, so moderation and antispam functionality works as normal. Two-View layout provides one view for submitting entries and another for reading them. Automatic paging of entries to customizable length. Show icons for country, browser, and OS in visitor signatures. Admin-panel stylesheet selector allows easy skinning to suit your theme. No bloat: Uses existing WordPress faculties so no custom database tables are required. Simple PHP template function allows programmers to manually embed standalone guestbooks in any template they wish. For a Demo, see the plugin’s homepage. Donate Many hours have gone into developing & maintaining this plugin, far beyond my own personal needs. If you find it useful, a donation would be greatly appreciated. Privacy This plugin uses standard WordPress comments for its entries – it is essentially a fancy whole-page comment form skin. It does not collect any data beyond that which would normally be included in standard WordPress comments. Please refer to the WordPress documentation for details on what information is stored with comments. Support Please direct all support requests here
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C