The Simple Iframe WordPress plugin before 1.2.0 does not properly validate one of its WordPress block attributes content, which may allow users whose role is at least that of a contributor to conduct Stored Cross-Site Scripting attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Simple_iframe | Simple_iframe_project | * | 1.2.0 (excluding) |