ZeroHour

CVE-2023-2964

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p44
Published
()
Modified
Description

The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.

Vendors
simple iframe project
Products
simple iframe
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.