Advanced iFrame <= 2024.5 - Unauthenticated Settings Update

2025-03-25 00:00
Peter Thaleikis

Strategic Overview

Status
Patched in 2025.0
Affected PluginAdvanced iFrame
Affected Version<= 2024.5
CVSS5.3Medium
CVECVE-2025-1440
View all Advanced iFrame vulnerabilities

Vulnerability Overview

The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.

Technical Analysis

REMEDIATION: Update to version 2025.0, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C