First published: Wed Mar 26 2025(Updated: )
The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Advanced iFrame | <=2024.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1440 is classified as a high-severity vulnerability due to its potential for unauthorized access and manipulation.
To fix CVE-2025-1440, update the Advanced iFrame plugin to the latest version beyond 2024.5.
CVE-2025-1440 affects all versions of the Advanced iFrame plugin up to and including version 2024.5.
CVE-2025-1440 can be exploited by unauthenticated attackers due to insufficient restrictions in the aip_map_url_callback() function.
The vulnerability CVE-2025-1440 is caused by insufficient restrictions that allow excessive creation of options in the Advanced iFrame plugin.