The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:52:25.423Z

Updated: 2024-01-16T15:52:25.423Z

Reserved: 2022-04-29T09:30:03.602Z


Link: CVE-2021-4227

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-16T16:15:09.270

Modified: 2024-01-19T15:29:25.803


Link: CVE-2021-4227

JSON object: View

cve-icon Redhat Information

No data.

CWE