plugin

Insert Or Embed Articulate Content Into Wordpress Vulnerabilities

26 known security issues reported for the Insert Or Embed Articulate Content Into Wordpress WordPress plugin. Most recent disclosed Jul 24, 2026.

5 high 5 medium

Running Insert Or Embed Articulate Content Into Wordpress on your site? Check whether your installed version is affected.

Scan your site free

Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Authenticated (Editor+) Arbitrary File Upload

high

The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 4.3000000027. This is due to missing file type validation. This makes it possible for authenticated attackers, with editor-level access and above, to upload arbitrary files...

CVSS:
7.2
Affected:
up to 4.3000000027
Fix:
No patched version reported
Disclosed:
Jul 24, 2026

CVE-2026-16060 on NVD →

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] <= 4.3000000025 (unfixed)

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress allows Upload a Web Shell to a Web Server. This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000025.

Affected:
up to 4.3000000025
Fix:
No patched version reported
Disclosed:
Apr 10, 2025

CVE-2025-32202 on NVD →

Insert or Embed Articulate Content into WordPress <= 4.3000000025 - Authenticated (Editor+) Arbitrary File Upload

high

The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.3000000025. This makes it possible for authenticated attackers, with Editor-level access and above, to upload arbitrary files on...

CVSS:
7.2
Affected:
up to 4.3000000025
Fixed in:
4.3000000026
Disclosed:
Apr 8, 2025

CVE-2025-32202 on NVD →

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000016

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 4.3000000016
Fixed in:
4.3000000016
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000024

unknown

[en] The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.

Affected:
up to 4.3000000024
Fixed in:
4.3000000024
Disclosed:
Jul 15, 2024

CVE-2024-5630 on NVD →

Insert or Embed Articulate Content into WordPress <= 4.3000000023 - Authenticated (Author+) Arbitrary File Upload

high

The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to arbitrary file uploads through insecure file uploads in a zip archive in all versions up to, and including, 4.3000000023. This makes it possible for unauthenticated attackers to upload zip files containing phar files on the affe...

CVSS:
8.8
Affected:
up to 4.3000000023
Fixed in:
4.3000000024
Disclosed:
Jun 24, 2024

CVE-2024-5630 on NVD →

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000025

unknown

[en] The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.

Affected:
up to 4.3000000025
Fixed in:
4.3000000025
Disclosed:
Jun 4, 2024

CVE-2024-0756 on NVD →

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000024

unknown

[en] The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files

Affected:
up to 4.3000000024
Fixed in:
4.3000000024
Disclosed:
Jun 4, 2024

CVE-2024-0757 on NVD →

Insert or Embed Articulate Content into WordPress <= 4.3000000023 - Authenticated (Author+) Stored Cross-Site Scripting via Code Injection

medium

The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via e-Learning widget file upload in all versions up to, and including, 4.3000000023 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...

CVSS:
6.4
Affected:
up to 4.3000000023
Fixed in:
4.3000000025
Disclosed:
May 14, 2024

CVE-2024-0756 on NVD →

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000023

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021.

Affected:
up to 4.3000000023
Fixed in:
4.3000000023
Disclosed:
Dec 21, 2023

CVE-2023-50824 on NVD →

Insert or Embed Articulate Content into WordPress <= 4.3000000021 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

medium

The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.3000000021 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 4.3000000021
Fixed in:
4.3000000023
Disclosed:
Dec 19, 2023

CVE-2023-50824 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 4.3000000020
Fixed in:
4.3000000021
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 4.3000000016
Fixed in:
4.3000000016
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000016

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 4.3000000016
Fixed in:
4.3000000016
Disclosed:
Mar 4, 2022

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000016

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Insert or Embed Articulate Content into WordPress plugin (versions <= 4.3000000015).

Affected:
up to 4.3000000016
Fixed in:
4.3000000016
Disclosed:
Feb 28, 2022

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000016

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Insert or Embed Articulate Content into WordPress plugin (versions <= 4.3000000015).

Affected:
up to 4.3000000016
Fixed in:
4.3000000016
Disclosed:
Feb 28, 2022

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.2999

unknown

[en] The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.

Affected:
up to 4.2999
Fixed in:
4.2999
Disclosed:
Aug 27, 2019

CVE-2019-15649 on NVD →

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.29991

unknown

[en] The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.

Affected:
up to 4.29991
Fixed in:
4.29991
Disclosed:
Aug 27, 2019

CVE-2019-15648 on NVD →

Insert or Embed Articulate Content into WordPress < 4.29991 - Directory Traversal

medium

The Insert or Embed Articulate Content into WordPress plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.2999 via the rename_dir. This allows authenticated user with a role as low as subscriber to delete and rename arbitrary folders.

CVSS:
6.5
Affected:
up to 4.29991
Fixed in:
4.29991
Disclosed:
Jul 2, 2019

CVE-2019-15648 on NVD →

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.2999

unknown

Authenticated Remote Code Execution (RCE) vulnerability found in Insert or Embed Articulate Content into WordPress plugin (versions <= 4.2998).

Affected:
up to 4.2999
Fixed in:
4.2999
Disclosed:
Jul 2, 2019

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.29991

unknown

Authenticated Arbitrary Folder Deletion and Rename vulnerability found in Insert or Embed Articulate Content into WordPress plugin (versions <= 4.2999).

Affected:
up to 4.29991
Fixed in:
4.29991
Disclosed:
Jul 2, 2019

Insert or Embed Articulate Content into WordPress < 4.2999 - Arbitrary File Upload

high

The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.

CVSS:
8.8
Affected:
up to 4.2999
Fixed in:
4.2999
Disclosed:
Jun 11, 2019

CVE-2019-15649 on NVD →

Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update

high

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...

CVSS:
8.8
Affected:
up to 4.2997
Fixed in:
4.2997
Disclosed:
Feb 25, 2019

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.2997

unknown

The Freemius SDK for WordPress is vulnerable to authorization bypass due to a missing capability check on the _get_db_option and _set_db_option functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change site settings and...

Affected:
up to 4.2997
Fixed in:
4.2997
Disclosed:
Feb 25, 2019

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.2997

unknown

The library, used in numerous plugins, does not have proper authorisation when updating blog options, allowing any authenticated users, such as subscriber to update arbitrary options

Affected:
up to 4.2997
Fixed in:
4.2997

Insert or Embed Articulate Content into WordPress [insert-or-embed-articulate-content-into-wordpress] < 4.3000000021

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 4.3000000021
Fixed in:
4.3000000021

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database