The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2024-06-04T14:28:07.852Z

Updated: 2024-06-05T13:54:08.704Z

Reserved: 2024-01-19T17:21:50.587Z


Link: CVE-2024-0756

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-06-04T15:15:44.893

Modified: 2024-06-05T19:49:50.213


Link: CVE-2024-0756

JSON object: View

cve-icon Redhat Information

No data.

CWE