Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Advanced iFrame — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
Estado de mantenimiento
- Última versión conocida: 2026.2
Vulnerabilidades conocidas
15 CVEs conocidos registrados para Advanced iFrame.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-6742
|
Advanced iFrame [advanced-iframe] < 2026.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 2026.2
|
2026.2 |
2026-07-07 |
✓ corregido en la última versión
|
|
CVE-2026-25412
|
Advanced iFrame [advanced-iframe] <= 2025.10 (unfixed) |
— |
Desconocido
|
< 2025.10
|
2025.10 |
2026-02-19 |
✓ corregido en la última versión
|
|
CVE-2026-25453
|
Advanced iFrame [advanced-iframe] < 2026.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 2026.0
|
2026.0 |
2026-01-19 |
✓ corregido en la última versión
|
|
CVE-2024-4365
|
Advanced iFrame [advanced-iframe] < 2024.4 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 2024.4
|
2024.4 |
2024-05-22 |
✓ corregido en la última versión
|
|
CVE-2024-32079
|
Advanced iFrame [advanced-iframe] < 2024.3 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 2024.3
|
2024.3 |
2024-04-11 |
✓ corregido en la última versión
|
|
CVE-2024-1341
|
Advanced iFrame [advanced-iframe] < 2024.2 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2024.2
|
2024.2 |
2024-02-28 |
✓ corregido en la última versión
|
|
CVE-2024-24870
|
Advanced iFrame [advanced-iframe] < 2024.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 2024.0
|
2024.0 |
2024-02-05 |
✓ corregido en la última versión
|
|
CVE-2023-51690
|
Advanced iFrame [advanced-iframe] < 2023.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,5
|
< 2023.9
|
2023.9 |
2024-02-01 |
✓ corregido en la última versión
|
CVE-2026-6742
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in all versions up to, and including, 2026.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2026-25453
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2025.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-4365
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_direct’ parameter in versions up to, and including, 2024.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-32079
Update the WordPress Advanced iFrame plugin to the latest available version (at least 2024.3).
Byeongjun Jo discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced iFrame Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2024.3.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-1341
Update the WordPress Advanced iFrame plugin to the latest available version (at least 2024.2).
Fariq Fadillah Gusti Insani (fariqfgi) discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced iFrame Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2024.2.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2024-24870
Update the WordPress Advanced iFrame plugin to the latest available version (at least 2024.0).
LVT-tholv2k discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced iFrame Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2024.0.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-51690
Update the WordPress Advanced iFrame plugin to the latest available version (at least 2023.9).
LVT-tholv2k discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced iFrame Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2023.9.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
+ 7 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2023-7069
|
Advanced iFrame [advanced-iframe] < 2024.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2024.0
|
2024.0 |
2024-01-31 |
✓ corregido en la última versión
|
|
CVE-2023-4775
|
Advanced iFrame [advanced-iframe] < 2023.9 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2023.9
|
2023.9 |
2023-11-09 |
✓ corregido en la última versión
|
|
CVE-2025-1440
|
Advanced iFrame [advanced-iframe] < 2025.0 |
Validación incorrecta de la entrada |
Media
5,3
|
< 2025.0
|
2025.0 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2025-1439
|
Advanced iFrame [advanced-iframe] < 2025.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2025.0
|
2025.0 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2025-1437
|
Advanced iFrame [advanced-iframe] < 2025.0 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2025.0
|
2025.0 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2025-6987
|
Advanced iFrame [advanced-iframe] < 2025.6 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,4
|
< 2025.6
|
2025.6 |
0000-00-00 |
✓ corregido en la última versión
|
|
CVE-2025-8089
|
Advanced iFrame [advanced-iframe] < 2025.7 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
5,4
|
< 2025.7
|
2025.7 |
0000-00-00 |
✓ corregido en la última versión
|
CVE-2023-7069
Update the WordPress Advanced iFrame plugin to the latest available version (at least 2024.0).
Webbernaut discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced iFrame Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2024.0.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2023-4775
Update the WordPress Advanced iFrame plugin to the latest available version (at least 2023.9).
István Márton discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Advanced iFrame Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 2023.9.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2025-1440
The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-1439
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2024.5 due to insufficient input sanitization and output escaping on user supplied attributes through the 'src' attribute when the src supplied returns a header with an injected value . This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-1437
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This was partially patched in version 2024.5, and later improved in version 2025.3.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-6987
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe' shortcode in all versions up to, and including, 2025.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-8089
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in version less than, or equal to, 2025.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Cómo solucionarlo
Mantén Advanced iFrame actualizado — 2026.2 es la última versión en wordpress.org, y cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en").
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.