WordPress security by component
Advanced iFrame
Plugin description
Advanced iFrame is a WordPress component with 15 published CVE records in this archive. The latest tracked vulnerability was published Jul 08, 2026; the highest published CVSS base score is 6.5.
Plugin slug:
advanced-iframeLatest vulnerability
CVE-2026-6742: Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2026.1.
| Safe version |
|
||
|---|---|---|---|
| Jul 08, 2026 |
CVE-2026-6742
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2026.1.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25453
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 16, 2025 |
CVE-2025-8089
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jul 26, 2025 |
CVE-2025-6987
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Mar 26, 2025 |
CVE-2025-1440
Advanced iFrame: A security weakness
Advanced iFrame is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Mar 26, 2025 |
CVE-2025-1439
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 26, 2025 |
CVE-2025-1437
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| May 23, 2024 |
CVE-2024-4365
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 15, 2024 |
CVE-2024-32079
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 29, 2024 |
CVE-2024-1341
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE4.9
NVD5.4
|
| Feb 05, 2024 |
CVE-2024-24870
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Feb 01, 2024 |
CVE-2023-51690
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Feb 01, 2024 |
CVE-2023-7069
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Nov 13, 2023 |
CVE-2023-4775
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 07, 2022 |
CVE-2021-24953
Advanced iFrame: Cross-site scripting
Advanced iFrame is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVEPending
NVD6.1
|