CVE-2021-24953

CVE-2021-24953: Advanced iFrame < 2022 - Reflected Cross-Site Scripting

Vendor Unknown
Product Advanced iFrame
Weakness CWE-79 · XSS
Published March 7, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

Key dates

02Disclosure timeline

March 7, 2022 CVE published
August 3, 2024 Record updated