The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-06-04T14:28:07.852Z

Updated: 2024-08-01T18:18:17.955Z

Reserved: 2024-01-19T17:21:50.587Z

Link: CVE-2024-0756

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:17.955Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-04T15:15:44.893

Modified: 2024-06-05T19:49:50.213

Link: CVE-2024-0756

cve-icon Redhat

No data.