PT-2024-15797 · WordPress · Insert/Embed Articulate Content Into Wordpress

Dmitry Ignatyev

·

Published

2024-06-04

·

Updated

2026-03-03

·

CVE-2024-0756

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Insert or Embed Articulate Content into WordPress plugin versions through 4.3000000023
Description The issue lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.
Recommendations For versions through 4.3000000023, consider disabling the iframe addition feature until a patch is available. Restrict access to the iframe functionality to minimize the risk of exploitation. Avoid using the plugin to add iframes from untrusted sources until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-0756

Affected Products

Insert/Embed Articulate Content Into Wordpress