MEDIUM
Simple Iframe < 1.2.0 - Contributor+ Stored XSS
Published Jul 10, 2023
5.4
MEDIUMCVSS 3.1
EPSS 0.54%
Description
The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.
Affected products
- Vendor n/a Product Simple Iframe Defaultunaffected
- Version 0StatusaffectedConstraints<1.2.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Simple Iframe | unaffected |
|
- < 1.2.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34410 Advisory
- https://wpscan.com/vulnerability/97aac334-5323-41bb-90f0-d180bcc9162f exploitvdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34410 | Advisory | |
| https://wpscan.com/vulnerability/97aac334-5323-41bb-90f0-d180bcc9162f | exploitvdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Jul 10, 2023
Updated Apr 23, 2025
Reserved May 29, 2023
Link CVE-2023-2964
CISA Vulnrichment
Updated Apr 23, 2025
ENISA EUVD
EUVD-2023-34410 Assigner WPScan
Published Jul 10, 2023
Updated Apr 23, 2025
Exploited since n/a
Link EUVD-2023-34410