iframe

The Iframe shortcode is a replacement for the Iframe HTML tag, which WordPress removes for security reasons. It accepts the same parameters as the Iframe HTML tag and can be used to embed content from YouTube, Vimeo, Google Maps, or any external page. The Embed shortcode is a core WordPress feature that can embed content from various resources via direct links. However, it is important to note that HTTP pages cannot be embedded into HTTPS pages and vice versa. The protocol for the parent and embedded page should match.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in iframe 5.0

    Fixed

    The plugin called "iframe" used in WordPress can be hacked by malicious people. This is because it does not properly check for harmful code and does not protect against it when adding in certain feat...

    Read More
  • Input validation vulnerability in iframe 5.0

    Fixed

    The iframe plugin used in WordPress has a security issue called Stored Cross-Site Scripting. This means that anyone with Contributor-level access or higher can insert harmful web scripts into pages, ...

    Read More
  • Input validation vulnerability in iframe 4.8

    Fixed

    The iFrame plugin for WordPress, up to version 4.8, is vulnerable to a type of security issue called Stored Cross-Site Scripting. This means that attackers with contributor-level access and above can...

    Read More
  • Input validation vulnerability in iframe 4.6

    Fixed

    The WordPress iframe plugin has a security vulnerability that allows attackers with contributor-level permission and above to inject malicious web scripts into pages. This vulnerability affects versi...

    Read More
  • Input validation vulnerability in iframe 3.0

    Fixed

    The iFrame plugin for WordPress has a security vulnerability that can be exploited by unauthenticated attackers. If they can get a user to click on a link, they can inject web scripts that will execu...

    Read More
  • Input validation vulnerability in iframe 4.0

    Fixed

    Read More
  • Input validation vulnerability in iframe 4.4

    Fixed

    The version of WordPress before 4.5 did not check if a URL was safe when using the iframe plugin.

    Read More