PLUGIN SECURITY
Is Advanced iFrame safe?
Include content the way YOU like in an iframe that can hide and modify elements, does auto-height, forward parameters and does many, many more...
What this plugin does
- Slug:
advanced-iframe - Author: mdempfle
- 40000+ active installs
- 88/100 rating (54 reviews on wordpress.org)
- 2453929 all-time downloads
- On WordPress.org since 2011-07-22
embediframemodify cssresizeshortcode
Maintenance status
- Latest known version: 2026.2
- Last updated: 2026-06-02 6:13pm GMT
- Tested up to WordPress: 7.0.4
- Requires PHP: 7.4+
Known vulnerabilities
16 known CVEs on file for Advanced iFrame.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-25412 | Advanced iFrame [advanced-iframe] <= 2025.10 (unfixed) | — | Unknown | < 2025.10 | 2025.10 | 2026-02-19 | ✓ fixed in latest |
| CVE-2026-25453 | Advanced iFrame [advanced-iframe] < 2026.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2026.0 | 2026.0 | 2026-01-19 | ✓ fixed in latest |
| CVE-2026-6742 | Advanced iFrame [advanced-iframe] < 2026.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2026.2 | 2026.2 | 2026-01-19 | ✓ fixed in latest |
| CVE-2024-4365 | Advanced iFrame [advanced-iframe] < 2024.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2024.4 | 2024.4 | 2024-05-22 | ✓ fixed in latest |
| CVE-2024-32079 | Advanced iFrame [advanced-iframe] < 2024.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2024.3 | 2024.3 | 2024-04-11 | ✓ fixed in latest |
| CVE-2024-1341 | Advanced iFrame [advanced-iframe] < 2024.2 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2024.2 | 2024.2 | 2024-02-28 | ✓ fixed in latest |
| CVE-2024-24870 | Advanced iFrame [advanced-iframe] < 2024.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2024.0 | 2024.0 | 2024-02-05 | ✓ fixed in latest |
| CVE-2023-51690 | Advanced iFrame [advanced-iframe] < 2023.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2023.9 | 2023.9 | 2024-02-01 | ✓ fixed in latest |
+ 13 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-7069 | Advanced iFrame [advanced-iframe] < 2024.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2024.0 | 2024.0 | 2024-01-31 | ✓ fixed in latest |
| CVE-2023-4775 | Advanced iFrame [advanced-iframe] < 2023.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2023.9 | 2023.9 | 2023-11-09 | ✓ fixed in latest |
| — | Advanced iFrame [advanced-iframe] < 2025.0 | Improper Input Validation | Medium 5.3 | < 2025.0 | 2025.0 | 0000-00-00 | ✓ fixed in latest |
| — | Advanced iFrame [advanced-iframe] < 2025.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2025.0 | 2025.0 | 0000-00-00 | ✓ fixed in latest |
| — | Advanced iFrame [advanced-iframe] < 2025.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2025.0 | 2025.0 | 0000-00-00 | ✓ fixed in latest |
| — | Advanced iFrame [advanced-iframe] < 2025.6 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2025.6 | 2025.6 | 0000-00-00 | ✓ fixed in latest |
| — | Advanced iFrame [advanced-iframe] < 2025.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2025.7 | 2025.7 | 0000-00-00 | ✓ fixed in latest |
| CVE-2021-24953 | Advanced iFrame < 2022 - Reflected Cross-Site Scripting | — | Unknown | < 2022 | 2022 | — | ✓ fixed in latest |
| CVE-2025-1439 | Advanced iFrame < 2025.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Host Header | — | Unknown | < 2025.0 | 2025.0 | — | ✓ fixed in latest |
| CVE-2025-1437 | Advanced iFrame < 2025.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 2025.3 | 2025.3 | — | ✓ fixed in latest |
| CVE-2025-1440 | Advanced iFrame < 2025.0 - Unauthenticated Settings Update | — | Unknown | < 2025.0 | 2025.0 | — | ✓ fixed in latest |
| CVE-2025-6987 | Advanced iFrame < 2025.6 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 2025.6 | 2025.6 | — | ✓ fixed in latest |
| CVE-2025-8089 | Advanced iFrame < 2025.7 - Authenticated (Contributor+) Stored Cross-Site Scripting | — | Unknown | < 2025.7 | 2025.7 | — | ✓ fixed in latest |
How to fix it
Keep Advanced iFrame updated — 2026.2 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents — 100000+ active installs — 96/100 (306) — max PHP 8.4
- iframe — 60000+ active installs — 88/100 (56) — max PHP 8.4
- Insert Pages — 30000+ active installs — 96/100 (71) — max PHP 8.4
- Compact WP Audio Player — 20000+ active installs — 82/100 (69) — max PHP 8.4
- Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … — 20000+ active installs — 84/100 (169)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.