Advanced iFrame <= 2024.5 - Unauthenticated Settings Update
Vulnerability Description
The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1440
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Peter Thaleikis
References
More from mdempfle
View All →Affected Vendor
mdempfle
View all reports →