plugin

Advanced Iframe Vulnerabilities

27 known security issues reported for the Advanced Iframe WordPress plugin. Most recent disclosed Jul 7, 2026.

13 medium

Running Advanced Iframe on your site? Check whether your installed version is affected.

Scan your site free

Advanced iFrame <= 2026.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block 'additional' Attribute

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to in...

CVSS:
6.4
Affected:
up to 2026.1
Fixed in:
2026.2
Disclosed:
Jul 7, 2026

CVE-2026-6742 on NVD →

Advanced iFrame [advanced-iframe] <= 2025.10 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdempfle Advanced iFrame advanced-iframe allows DOM-Based XSS.This issue affects Advanced iFrame: from n/a through <= 2025.10.

Affected:
up to 2025.10
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25453 on NVD →

Advanced iFrame [advanced-iframe] <= 2025.10 (unfixed)

unknown

[en] Missing Authorization vulnerability in mdempfle Advanced iFrame advanced-iframe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced iFrame: from n/a through <= 2025.10.

Affected:
up to 2025.10
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25412 on NVD →

Advanced iFrame <= 2025.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2025.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 2025.10
Fixed in:
2026.0
Disclosed:
Jan 19, 2026

CVE-2026-25453 on NVD →

Advanced iFrame <= 2025.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to injec...

CVSS:
5.4
Affected:
up to 2025.6
Fixed in:
2025.7
Disclosed:
Aug 15, 2025

CVE-2025-8089 on NVD →

Advanced iFrame <= 2025.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2025.5
Fixed in:
2025.6
Disclosed:
Jul 25, 2025

CVE-2025-6987 on NVD →

Advanced iFrame <= 2024.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Host Header

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to insufficient input sanitization and output escaping on user supplied attributes through the 'src' attribute when the src supplied returns...

CVSS:
6.4
Affected:
up to 2024.5
Fixed in:
2025.0
Disclosed:
Mar 25, 2025

CVE-2025-1439 on NVD →

Advanced iFrame <= 2025.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with...

CVSS:
6.4
Affected:
up to 2025.2
Fixed in:
2025.3
Disclosed:
Mar 25, 2025

CVE-2025-1437 on NVD →

Advanced iFrame <= 2024.5 - Unauthenticated Settings Update

medium

The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option...

CVSS:
5.3
Affected:
up to 2024.5
Fixed in:
2025.0
Disclosed:
Mar 25, 2025

CVE-2025-1440 on NVD →

Advanced iFrame [advanced-iframe] < 2024.4

unknown

[en] The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_direct’ parameter in versions up to, and including, 2024.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level pe...

Affected:
up to 2024.4
Fixed in:
2024.4
Disclosed:
May 23, 2024

CVE-2024-4365 on NVD →

Advanced iFrame <= 2024.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_direct’ parameter in versions up to, and including, 2024.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permiss...

CVSS:
6.4
Affected:
up to 2024.3
Fixed in:
2024.4
Disclosed:
May 22, 2024

CVE-2024-4365 on NVD →

Advanced iFrame [advanced-iframe] < 2024.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2024.2.

Affected:
up to 2024.3
Fixed in:
2024.3
Disclosed:
Apr 15, 2024

CVE-2024-32079 on NVD →

Advanced iFrame <= 2024.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2024.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
6.4
Affected:
up to 2024.2
Fixed in:
2024.3
Disclosed:
Apr 11, 2024

CVE-2024-32079 on NVD →

Advanced iFrame [advanced-iframe] < 2024.2

unknown

[en] The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up to, and including, 2024.1 due to the plugin allowing users to include JS files from external sources through the additional_js attribute. This makes it possible for au...

Affected:
up to 2024.2
Fixed in:
2024.2
Disclosed:
Feb 29, 2024

CVE-2024-1341 on NVD →

Advanced iFrame <= 2024.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up to, and including, 2024.1 due to the plugin allowing users to include JS files from external sources through the additional_js attribute. This makes it possible for authent...

CVSS:
4.9
Affected:
up to 2024.1
Fixed in:
2024.2
Disclosed:
Feb 28, 2024

CVE-2024-1341 on NVD →

Advanced iFrame [advanced-iframe] < 2024.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.10.

Affected:
up to 2024.0
Fixed in:
2024.0
Disclosed:
Feb 5, 2024

CVE-2024-24870 on NVD →

Advanced iFrame [advanced-iframe] < 2023.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a through 2023.8.

Affected:
up to 2023.9
Fixed in:
2023.9
Disclosed:
Feb 1, 2024

CVE-2023-51690 on NVD →

Advanced iFrame [advanced-iframe] < 2024.0

unknown

[en] The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2023.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers...

Affected:
up to 2024.0
Fixed in:
2024.0
Disclosed:
Feb 1, 2024

CVE-2023-7069 on NVD →

Advanced iFrame <= 2023.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2023.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with...

CVSS:
6.4
Affected:
up to 2023.10
Fixed in:
2024.0
Disclosed:
Jan 31, 2024

CVE-2023-7069 on NVD →

Advanced iFrame [advanced-iframe] < 2023.9

unknown

[en] The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contribu...

Affected:
up to 2023.9
Fixed in:
2023.9
Disclosed:
Nov 13, 2023

CVE-2023-4775 on NVD →

Advanced iFrame <= 2023.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'advanced_iframe' shortcode in versions up to, and including, 2023.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-l...

CVSS:
6.4
Affected:
up to 2023.8
Fixed in:
2023.9
Disclosed:
Nov 9, 2023

CVE-2023-4775 on NVD →

Advanced iFrame <= 2021.9 Reflected Cross-Site Scripting

medium

The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 2021.9
Fixed in:
2022
Disclosed:
Feb 2, 2022

CVE-2021-24953 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database