ark-commenteditor <= 2.15.6 - iframe Injection
highThe ark-commenteditor plugin for WordPress is vulnerable to iFrame Injection in versions up to, and including 2.15.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject iFrame elements in comments that will load pages from any source.
- CVSS:
- 7.2
- Affected:
- up to 2.15.6
- Fix:
- No patched version reported
- Disclosed:
- Sep 23, 2021