The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-16T15:52:25.423Z
Updated: 2024-08-03T17:23:08.904Z
Reserved: 2022-04-29T09:30:03.602Z
Link: CVE-2021-4227
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2024-01-16T16:15:09.270
Modified: 2024-01-19T15:29:25.803
Link: CVE-2021-4227
Redhat
No data.