Description
The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-34085 | The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section |
References
History
Mon, 02 Jun 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-02T15:10:29.086Z
Reserved: 2022-04-29T09:30:03.602Z
Link: CVE-2021-4227
Updated: 2024-08-03T17:23:08.904Z
Status : Modified
Published: 2024-01-16T16:15:09.270
Modified: 2025-06-02T16:15:23.187
Link: CVE-2021-4227
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD