CVE-2023-2964

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
10/07/2023
Last modified:
23/04/2025

Description

The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attribute's content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:simple_iframe_project:simple_iframe:*:*:*:*:*:wordpress:*:* 1.2.0 (excluding)