Vulnerability Description
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elearningfreak | Insert Or Embed Articulate Content | <= 4.3000000023 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/9130a42d-fca3-4f9c-ab97-d5e0a7a5cef2/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/9130a42d-fca3-4f9c-ab97-d5e0a7a5cef2/ExploitThird Party Advisory
FAQ
What is CVE-2024-0756?
CVE-2024-0756 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitra...
How severe is CVE-2024-0756?
CVE-2024-0756 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0756?
Check the references section above for vendor advisories and patch information. Affected products include: Elearningfreak Insert Or Embed Articulate Content.