Extension WordPress
Vulnérabilités iframe
Cette page rassemble les failles publiées pour iframe, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de iframe
7 fiches
iframe <= 5.0 – Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode
The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to and including 5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-5.0
5.1
22/05/2024
iframe <= 5.0 – Authenticated (Contributor+ Stored Cross-Site Scripting
The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
*-5.0
5.1
14/05/2024
iFrame <= 4.8 – Authenticated (Contributor+) Stored Cross-Site Scripting via srcdoc
The iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the srcdoc parameter in versions up to, and including, 4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-4.8
4.9
28/12/2023
iframe <= 4.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'iframe' Shortcode
The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `iframe` shortcode in versions up to, and including, 4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
*-4.6
4.7
25/09/2023
iframe <= 4.4 – Authenticated Stored Cross Site Scripting
The iframe plugin before 4.5 for WordPress does not sanitize a URL.
*-4.4
4.5
07/05/2020
iFrame <= 3.0 – Reflected Cross-Site Scripting
The iFrame plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘get_params_from_url’ option in versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-3.0
4.0
11/08/2015
iFrame <= 4.0 – Stored Cross-Site Scripting
The iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘onload’ attribute found in the iFrame shortcode in versions up to, and including, 4.0 due to insufficient input sanitization and output escaping. This makes it…
*-4.0
4.1
10/08/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.