CVE-2025-1440

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 20

Summary

CVE-2025-1440: Unauthenticated attackers can exploit the Advanced iFrame plugin for WordPress by excessively creating options on the aip_map_url_callback() function, available in versions up to 2024.5. This vulnerability stems from insufficient restrictions, allowing malicious actors to update the advancediFrameParameterData option with unvalidated data. The impact of this issue includes potential harm to website functionality and security. It is crucial for WordPress users to update the plugin to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share