CVE-2024-34805
The iframe plugin for WordPress through version 5.0 contains a stored cross-site scripting flaw caused by inadequate sanitization of user input and insufficient escaping of output. Attackers with at least Contributor-level permissions can exploit this vulnerability to inject malicious scripts into pages, which then execute for any user viewing those pages. The vulnerability affects all versions up to and including 5.0, with version 5.1 containing the fix.
Based on public CVE data (MITRE/NVD).