First published: Thu Feb 29 2024(Updated: )
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up to, and including, 2024.1 due to the plugin allowing users to include JS files from external sources through the additional_js attribute. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced iFrame | <=2024.1 | |
<2024.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1341 is classified as a medium severity vulnerability due to the risk of Stored Cross-Site Scripting.
To fix CVE-2024-1341, update the Advanced iFrame plugin to version 2024.2 or later.
CVE-2024-1341 affects all websites using the Advanced iFrame plugin up to version 2024.1 on WordPress.
The primary attack vector for CVE-2024-1341 is through the 'advanced_iframe' shortcode allowing external JS inclusion.
Yes, CVE-2024-1341 could potentially lead to a data breach by allowing attackers to execute malicious scripts.