ZeroHour

CVE-2021-4227

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p47
Published
()
Modified
Description

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section

Vendors
obg
Products
ark wysiwyg comment editor
Ecosystems
WordPress
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.