CVE-2024-0756

CVE-2024-0756: Insert or Embed Articulate Content into WordPress <= 4.3000000023 - Iframe Injection

Vendor Unknown
Product Insert or Embed Articulate Content into WordPress
Published June 4, 2024
Last update March 3, 2026

CVSS base score

What the vulnerability does

01Description

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.

Key dates

02Disclosure timeline

June 4, 2024 CVE published
March 3, 2026 Record updated