iframe Wrapper
iframe Wrapper has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for iframe Wrapper has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Muhammad Yudha - DJ. iframe Wrapper is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.0.5.
CVE-2025-49422iframe Wrapper <= 0.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
iframe Wrapper
Author
Aelora
iframes get a bad wrap, and rightly so in many cases. But when you want to embed one website inside of another one in a single step, they’re a really easy way to make it work. Usage Inside whatever post or page you want to embed another site, use the short code [iframeWrapper url=http://example.com] This will put an iframe linking to example.com into your page. The width will be 100% of the contain it’s in and the height will automatically adjust to the contents of the frame. This plugin was originally written to embed ProofBuddy sites within a WordPress theme without much fuss. But it should work well to embed any site within a WordPress theme.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C