Stored Cross-Site Scripting in Advanced iFrame Plugin for WordPress
CVE-2025-1439
6.4MEDIUM
What is CVE-2025-1439?
The Advanced iFrame plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the 'advanced_iframe' shortcode. This issue arises from inadequate input sanitization and output escaping of user-supplied attributes, particularly in the 'src' attribute. If an attacker with contributor-level access or higher injects a malicious script into a page, any user accessing that page may inadvertently execute the injected script. This vulnerability highlights the importance of proper validation processes to protect users from potential threats.
Affected Version(s)
Advanced iFrame * <= 2024.5