CVE-2024-0756

June 4, 2024, 4:57 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Insert or Embed Articulate Content into WordPress plugin

  • <= 4.3.000000023

Source

contact@wpscan.com

Tags

CVE-2024-0756 details

Published : June 4, 2024, 3:15 p.m.
Last Modified : June 4, 2024, 4:57 p.m.

Description

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
This website uses the NVD API, but is not approved or certified by it.