Advanced iFrame <= 2026.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block 'additional' Attribute
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to in...
- CVSS:
- 6.4
- Affected:
- up to 2026.1
- Fixed in:
- 2026.2
- Disclosed:
- Jul 7, 2026
CVE-2026-6742 on NVD →
Advanced iFrame [advanced-iframe] <= 2025.10 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced iFrame advanced-iframe allows DOM-Based XSS.This issue affects Advanced iFrame: from n/a through <= 2025.10.
- Affected:
- up to 2025.10
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25453 on NVD →
Advanced iFrame [advanced-iframe] <= 2025.10 (unfixed)
unknown
[en] Missing Authorization vulnerability in mdempfle Advanced iFrame advanced-iframe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced iFrame: from n/a through <= 2025.10.
- Affected:
- up to 2025.10
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-25412 on NVD →
Advanced iFrame <= 2025.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2025.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...
- CVSS:
- 6.4
- Affected:
- up to 2025.10
- Fixed in:
- 2026.0
- Disclosed:
- Jan 19, 2026
CVE-2026-25453 on NVD →
Advanced iFrame <= 2025.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...
- CVSS:
- 5.4
- Affected:
- up to 2025.6
- Fixed in:
- 2025.7
- Disclosed:
- Aug 15, 2025
CVE-2025-8089 on NVD →
Advanced iFrame <= 2025.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 2025.5
- Fixed in:
- 2025.6
- Disclosed:
- Jul 25, 2025
CVE-2025-6987 on NVD →
Advanced iFrame <= 2024.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Host Header
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to insufficient input sanitization and output escaping on user supplied attributes through the 'src' attribute when the src supplied returns...
- CVSS:
- 6.4
- Affected:
- up to 2024.5
- Fixed in:
- 2025.0
- Disclosed:
- Mar 25, 2025
CVE-2025-1439 on NVD →
Advanced iFrame <= 2025.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...
- CVSS:
- 6.4
- Affected:
- up to 2025.2
- Fixed in:
- 2025.3
- Disclosed:
- Mar 25, 2025
CVE-2025-1437 on NVD →
Advanced iFrame <= 2024.5 - Unauthenticated Settings Update
medium
The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option...
- CVSS:
- 5.3
- Affected:
- up to 2024.5
- Fixed in:
- 2025.0
- Disclosed:
- Mar 25, 2025
CVE-2025-1440 on NVD →
Advanced iFrame [advanced-iframe] < 2024.4
unknown
[en] The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_direct’ parameter in versions up to, and including, 2024.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level pe...
- Affected:
- up to 2024.4
- Fixed in:
- 2024.4
- Disclosed:
- May 23, 2024
CVE-2024-4365 on NVD →
Advanced iFrame <= 2024.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_direct’ parameter in versions up to, and including, 2024.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permiss...
- CVSS:
- 6.4
- Affected:
- up to 2024.3
- Fixed in:
- 2024.4
- Disclosed:
- May 22, 2024
CVE-2024-4365 on NVD →
Advanced iFrame [advanced-iframe] < 2024.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2024.2.
- Affected:
- up to 2024.3
- Fixed in:
- 2024.3
- Disclosed:
- Apr 15, 2024
CVE-2024-32079 on NVD →
Advanced iFrame <= 2024.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2024.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 6.4
- Affected:
- up to 2024.2
- Fixed in:
- 2024.3
- Disclosed:
- Apr 11, 2024
CVE-2024-32079 on NVD →
Advanced iFrame [advanced-iframe] < 2024.2
unknown
[en] The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up to, and including, 2024.1 due to the plugin allowing users to include JS files from external sources through the additional_js attribute. This makes it possible for au...
- Affected:
- up to 2024.2
- Fixed in:
- 2024.2
- Disclosed:
- Feb 29, 2024
CVE-2024-1341 on NVD →
Advanced iFrame <= 2024.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up to, and including, 2024.1 due to the plugin allowing users to include JS files from external sources through the additional_js attribute. This makes it possible for authent...
- CVSS:
- 4.9
- Affected:
- up to 2024.1
- Fixed in:
- 2024.2
- Disclosed:
- Feb 28, 2024
CVE-2024-1341 on NVD →
Advanced iFrame [advanced-iframe] < 2024.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.10.
- Affected:
- up to 2024.0
- Fixed in:
- 2024.0
- Disclosed:
- Feb 5, 2024
CVE-2024-24870 on NVD →
Advanced iFrame [advanced-iframe] < 2023.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.8.
- Affected:
- up to 2023.9
- Fixed in:
- 2023.9
- Disclosed:
- Feb 1, 2024
CVE-2023-51690 on NVD →
Advanced iFrame [advanced-iframe] < 2024.0
unknown
[en] The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2023.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...
- Affected:
- up to 2024.0
- Fixed in:
- 2024.0
- Disclosed:
- Feb 1, 2024
CVE-2023-7069 on NVD →
Advanced iFrame <= 2023.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2023.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with...
- CVSS:
- 6.4
- Affected:
- up to 2023.10
- Fixed in:
- 2024.0
- Disclosed:
- Jan 31, 2024
CVE-2023-7069 on NVD →
Advanced iFrame [advanced-iframe] < 2023.9
unknown
[en] The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contribu...
- Affected:
- up to 2023.9
- Fixed in:
- 2023.9
- Disclosed:
- Nov 13, 2023
CVE-2023-4775 on NVD →
Advanced iFrame <= 2023.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 2023.8
- Fixed in:
- 2023.9
- Disclosed:
- Nov 9, 2023
CVE-2023-4775 on NVD →
Advanced iFrame <= 2021.9 Reflected Cross-Site Scripting
medium
The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 2021.9
- Fixed in:
- 2022
- Disclosed:
- Feb 2, 2022
CVE-2021-24953 on NVD →
Advanced iFrame [advanced-iframe] < 2025.0
unknown
- Affected:
- up to 2025.0
- Fixed in:
- 2025.0
CVE-2025-1440 on NVD →
Advanced iFrame [advanced-iframe] < 2025.0
unknown
- Affected:
- up to 2025.0
- Fixed in:
- 2025.0
CVE-2025-1439 on NVD →
Advanced iFrame [advanced-iframe] < 2025.0
unknown
- Affected:
- up to 2025.0
- Fixed in:
- 2025.0
CVE-2025-1437 on NVD →
Advanced iFrame [advanced-iframe] < 2025.6
unknown
- Affected:
- up to 2025.6
- Fixed in:
- 2025.6
CVE-2025-6987 on NVD →
Advanced iFrame [advanced-iframe] < 2025.7
unknown
- Affected:
- up to 2025.7
- Fixed in:
- 2025.7
CVE-2025-8089 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database