Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-1440


The Advanced iFrame plugin for WordPress is vulnerable to unauthorized excessive creation of options on the aip_map_url_callback() function in all versions up to, and including, 2024.5 due to insufficient restrictions. This makes it possible for unauthenticated attackers to update the advancediFrameParameterData option with an excessive amount of unvalidated data.


Published

2025-03-26T10:15:15.260

Last Modified

2025-07-14T16:40:37.780

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tinywebgallery advanced_iframe < 2025.0 Yes

References