CVE-2024-0756
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to inject malicious iFrames into a WordPress page, which can load harmful content from any website. It occurs because the plugin does not properly check the URLs being added, so if an attacker has access to modify the content, they can exploit this weakness.
Technical Description
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Jun 4, 2024
almost 2 years ago
Last Modified
Mar 3, 2026
about 1 month ago
Vendor
elearningfreak
Product
insert or embed articulate content