5.3
CVE-2025-1440
- EPSS 0.35%
- Veröffentlicht 26.03.2025 09:21:51
- Zuletzt bearbeitet 14.07.2025 16:40:37
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Advanced iFrame <= 2024.5 - Unauthenticated Settings Update
The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.
Mögliche Gegenmaßnahme
Advanced iFrame: Update to version 2025.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Advanced iFrame
Version
*-2024.5
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tinywebgallery ≫ Advanced Iframe SwPlatformwordpress Version < 2025.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.569 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.