cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-10151,https://securityvulnerability.io/vulnerability/CVE-2024-10151,Stored Cross-Site Scripting in Auto iFrame WordPress Plugin,"The Auto iFrame WordPress plugin prior to version 2.0 exhibits a vulnerability where it fails to properly validate and escape certain shortcode attributes. This flaw enables users with contributor roles or higher permissions to execute Stored Cross-Site Scripting (XSS) attacks, potentially compromising website integrity and user data security. Utilizing this vulnerability, attackers can inject malicious scripts into posts or pages, affecting unsuspecting visitors.",Wordpress,Auto Iframe,,,0.0004299999854993075,false,,false,false,true,true,false,false,2025-01-08T06:00:12.427Z,0 CVE-2024-9449,https://securityvulnerability.io/vulnerability/CVE-2024-9449,Stored Cross-Site Scripting vulnerability in Auto iFrame plugin,"The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",Wordpress,Auto Iframe,6.4,MEDIUM,0.0006799999973736703,false,,false,false,false,,false,false,2024-10-09T06:44:38.096Z,0