CVE-2024-0756

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to inject malicious iFrames into a WordPress page, which can load harmful content from any website. It occurs because the plugin does not properly check the URLs being added, so if an attacker has access to modify the content, they can exploit this weakness.

Technical Description

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
Confidentiality ImpactLow
Integrity ImpactLow
Availability ImpactNone
ScopeChanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$741($500-$1K)
Vendor Response
Grade FPatched in 637 days

Quick Information

Published

Jun 4, 2024

almost 2 years ago

Last Modified

Mar 3, 2026

about 1 month ago

Vendor

elearningfreak

Product

insert or embed articulate content