PLUGIN SECURITY
Is Iframe safe?
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
What this plugin does
- Slug:
iframe - Author: webvitalii
- 60000+ active installs
- 88/100 rating (56 reviews on wordpress.org)
- 1929848 all-time downloads
- On WordPress.org since 2011-04-28
embedGoogle Mapsiframevimeoyoutube
Maintenance status
- Latest known version: 6.0
- Last updated: 2026-05-17 2:17am GMT
- Tested up to WordPress: 7.0.4
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
6 known CVEs on file for Iframe.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-6844 | iframe [iframe] < 5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.0 | < 5.1 | 5.1 | 2024-05-22 | ✓ fixed in latest |
| CVE-2024-34805 | iframe [iframe] < 5.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 5.1 | 5.1 | 2024-05-14 | ✓ fixed in latest |
| CVE-2023-52125 | iframe [iframe] < 4.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 4.9 | 4.9 | 2023-12-28 | ✓ fixed in latest |
| CVE-2023-4919 | iframe [iframe] < 4.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 4.7 | 4.7 | 2023-09-25 | ✓ fixed in latest |
| CVE-2020-12696 | iframe [iframe] < 4.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 4.5 | 4.5 | 2020-05-07 | ✓ fixed in latest |
| — | iframe [iframe] < 4.0 | — | Unknown | < 4.0 | 4.0 | 2015-08-11 | ✓ fixed in latest |
| CVE-2015-6738 | iframe [iframe] < 4.1 | — | Unknown | < 4.1 | 4.1 | 0000-00-00 | ✓ fixed in latest |
| — | iframe [iframe] < 4.0 | — | Unknown | < 4.0 | 4.0 | — | ✓ fixed in latest |
+ 3 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | iframe [iframe] < 4.0 | — | Unknown | < 4.0 | 4.0 | — | ✓ fixed in latest |
| — | iframe < 4.0 - Unauthenticated Reflected Cross-Site Scripting (XSS) | — | Unknown | < 4.0 | 4.0 | — | ✓ fixed in latest |
| — | iframe < 4.0 - Authenticated Stored Cross-Site Scripting (XSS) | — | Unknown | < 4.0 | 4.0 | — | ✓ fixed in latest |
How to fix it
Keep Iframe updated — 6.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- WP Go Maps – Google Map, OpenStreetMap, Leaflet Map — 300000+ active installs — 96/100 (3032) — max PHP 8.4
- EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents — 100000+ active installs — 96/100 (306) — max PHP 8.4
- WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters — 60000+ active installs — 86/100 (122) — max PHP 8.4
- WP Store Locator — 50000+ active installs — 96/100 (312) — max PHP 8.4
- Advanced iFrame — 40000+ active installs — 88/100 (54)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.