CVE-2025-1440
MEDIUMAdvanced iFrame < 2024.5 - Unauthenticated Excessive Option Creation in aip_map_url_callback
Title source: llmDescription
The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.
References (2)
Core 2
Core References
Scores
CVSS v3
5.3
EPSS
0.0026
EPSS Percentile
16.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (2)
mdempfle/Advanced iFrame
< 2024.5
tinywebgallery/advanced_iframe
< 2025.0
Published
Mar 26, 2025
Tracked Since
Feb 18, 2026