Input validation vulnerability in Advanced iFrame 2025.5

The Advanced iFrame plugin used in WordPress is at risk of being hacked through a type of attack called Stored Cross-Site Scripting. This can happen when the plugin’s ‘advanced_iframe’ shortcode is used, which is a feature that allows users to add custom content to their website. The problem is that the plugin does not properly clean or protect the information entered by users, which means that someone with the right level of access could insert malicious code that will run when someone visits the affected page.

Detected in:

Advanced iFrame fixed vulnerable versions: >= * <= 2025.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.