CVE-2015-6738
The iFrame plugin for WordPress through version 3.0 contains a reflected cross-site scripting vulnerability in the 'get_params_from_url' option caused by inadequate sanitization of input and escaping of output. An unauthenticated attacker could exploit this flaw to inject malicious scripts into web pages, which would execute if a user could be persuaded to click a specially crafted link.
Based on public CVE data (MITRE/NVD).