The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.
History

Wed, 26 Mar 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 09:45:00 +0000

Type Values Removed Values Added
Description The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.
Title Advanced iFrame <= 2024.5 - Unauthenticated Settings Update
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-03-26T09:21:51.286Z

Updated: 2025-03-26T17:36:49.548Z

Reserved: 2025-02-18T15:22:26.598Z

Link: CVE-2025-1440

cve-icon Vulnrichment

Updated: 2025-03-26T17:36:45.592Z

cve-icon NVD

Status : Received

Published: 2025-03-26T10:15:15.260

Modified: 2025-03-26T10:15:15.260

Link: CVE-2025-1440

cve-icon Redhat

No data.