Stored Cross-Site Scripting in Advanced iFrame Plugin for WordPress
CVE-2025-1439
What is CVE-2025-1439?
The Advanced iFrame plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the 'advanced_iframe' shortcode. This issue arises from inadequate input sanitization and output escaping of user-supplied attributes, particularly in the 'src' attribute. If an attacker with contributor-level access or higher injects a malicious script into a page, any user accessing that page may inadvertently execute the injected script. This vulnerability highlights the importance of proper validation processes to protect users from potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Advanced iFrame * <= 2024.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved