PT-2024-15797 · WordPress · Insert/Embed Articulate Content Into Wordpress
Dmitry Ignatyev
·
Published
2024-06-04
·
Updated
2026-03-03
·
CVE-2024-0756
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Insert or Embed Articulate Content into WordPress plugin versions through 4.3000000023
Description
The issue lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.
Recommendations
For versions through 4.3000000023, consider disabling the iframe addition feature until a patch is available. Restrict access to the iframe functionality to minimize the risk of exploitation. Avoid using the plugin to add iframes from untrusted sources until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insert/Embed Articulate Content Into Wordpress