The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-16T15:52:25.423Z
Updated: 2024-08-03T17:23:08.904Z
Reserved: 2022-04-29T09:30:03.602Z
Link: CVE-2021-4227

No data.

Status : Modified
Published: 2024-01-16T16:15:09.270
Modified: 2024-11-21T06:37:11.290
Link: CVE-2021-4227

No data.