Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Authenticated (Editor+) Arbitrary File Upload
high
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 4.3000000027. This is due to missing file type validation. This makes it possible for authenticated attackers, with editor-level access and above, to upload arbitrary files...
- CVSS:
- 7.2
- Affected:
- up to 4.3000000027
- Fix:
- No patched version reported
- Disclosed:
- Jul 24, 2026
CVE-2026-16060 on NVD →
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] <= 4.3000000025 (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress allows Upload a Web Shell to a Web Server. This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000025.
- Affected:
- up to 4.3000000025
- Fix:
- No patched version reported
- Disclosed:
- Apr 10, 2025
CVE-2025-32202 on NVD →
Insert or Embed Articulate Content into WordPress <= 4.3000000025 - Authenticated (Editor+) Arbitrary File Upload
high
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.3000000025. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on...
- CVSS:
- 7.2
- Affected:
- up to 4.3000000025
- Fixed in:
- 4.3000000026
- Disclosed:
- Apr 8, 2025
CVE-2025-32202 on NVD →
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000016
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 4.3000000016
- Fixed in:
- 4.3000000016
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000024
unknown
[en] The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
- Affected:
- up to 4.3000000024
- Fixed in:
- 4.3000000024
- Disclosed:
- Jul 15, 2024
CVE-2024-5630 on NVD →
Insert or Embed Articulate Content into WordPress <= 4.3000000023 - Authenticated (Author+) Arbitrary File Upload
high
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to arbitrary file uploads through insecure file uploads in a zip archive in all versions up to, and including, 4.3000000023. This makes it possible for unauthenticated attackers to upload zip files containing phar files on the affe...
- CVSS:
- 8.8
- Affected:
- up to 4.3000000023
- Fixed in:
- 4.3000000024
- Disclosed:
- Jun 24, 2024
CVE-2024-5630 on NVD →
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000025
unknown
[en] The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.
- Affected:
- up to 4.3000000025
- Fixed in:
- 4.3000000025
- Disclosed:
- Jun 4, 2024
CVE-2024-0756 on NVD →
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000024
unknown
[en] The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files
- Affected:
- up to 4.3000000024
- Fixed in:
- 4.3000000024
- Disclosed:
- Jun 4, 2024
CVE-2024-0757 on NVD →
Insert or Embed Articulate Content into WordPress <= 4.3000000023 - Authenticated (Author+) Stored Cross-Site Scripting via Code Injection
medium
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via e-Learning widget file upload in all versions up to, and including, 4.3000000023 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 6.4
- Affected:
- up to 4.3000000023
- Fixed in:
- 4.3000000025
- Disclosed:
- May 14, 2024
CVE-2024-0756 on NVD →
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000023
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021.
- Affected:
- up to 4.3000000023
- Fixed in:
- 4.3000000023
- Disclosed:
- Dec 21, 2023
CVE-2023-50824 on NVD →
Insert or Embed Articulate Content into WordPress <= 4.3000000021 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
medium
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3000000021 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 4.3000000021
- Fixed in:
- 4.3000000023
- Disclosed:
- Dec 19, 2023
CVE-2023-50824 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 4.3000000020
- Fixed in:
- 4.3000000021
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 4.3000000016
- Fixed in:
- 4.3000000016
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000016
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 4.3000000016
- Fixed in:
- 4.3000000016
- Disclosed:
- Mar 4, 2022
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000016
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress Insert or Embed Articulate Content into WordPress plugin (versions <= 4.3000000015).
- Affected:
- up to 4.3000000016
- Fixed in:
- 4.3000000016
- Disclosed:
- Feb 28, 2022
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000016
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Insert or Embed Articulate Content into WordPress plugin (versions <= 4.3000000015).
- Affected:
- up to 4.3000000016
- Fixed in:
- 4.3000000016
- Disclosed:
- Feb 28, 2022
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.2999
unknown
[en] The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.
- Affected:
- up to 4.2999
- Fixed in:
- 4.2999
- Disclosed:
- Aug 27, 2019
CVE-2019-15649 on NVD →
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.29991
unknown
[en] The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
- Affected:
- up to 4.29991
- Fixed in:
- 4.29991
- Disclosed:
- Aug 27, 2019
CVE-2019-15648 on NVD →
Insert or Embed Articulate Content into WordPress < 4.29991 - Directory Traversal
medium
The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.2999 via the rename_dir. This allows authenticated user with a role as low as subscriber to delete and rename arbitrary folders.
- CVSS:
- 6.5
- Affected:
- up to 4.29991
- Fixed in:
- 4.29991
- Disclosed:
- Jul 2, 2019
CVE-2019-15648 on NVD →
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.2999
unknown
Authenticated Remote Code Execution (RCE) vulnerability found in Insert or Embed Articulate Content into WordPress plugin (versions <= 4.2998).
- Affected:
- up to 4.2999
- Fixed in:
- 4.2999
- Disclosed:
- Jul 2, 2019
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.29991
unknown
Authenticated Arbitrary Folder Deletion and Rename vulnerability found in Insert or Embed Articulate Content into WordPress plugin (versions <= 4.2999).
- Affected:
- up to 4.29991
- Fixed in:
- 4.29991
- Disclosed:
- Jul 2, 2019
Insert or Embed Articulate Content into WordPress < 4.2999 - Arbitrary File Upload
high
The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.
- CVSS:
- 8.8
- Affected:
- up to 4.2999
- Fixed in:
- 4.2999
- Disclosed:
- Jun 11, 2019
CVE-2019-15649 on NVD →
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
high
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...
- CVSS:
- 8.8
- Affected:
- up to 4.2997
- Fixed in:
- 4.2997
- Disclosed:
- Feb 25, 2019
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.2997
unknown
The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...
- Affected:
- up to 4.2997
- Fixed in:
- 4.2997
- Disclosed:
- Feb 25, 2019
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.2997
unknown
The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options
- Affected:
- up to 4.2997
- Fixed in:
- 4.2997
Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000021
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 4.3000000021
- Fixed in:
- 4.3000000021
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database