5.3
CVSSv3

CVE-2021-4227

Published: 16/01/2024 Updated: 19/01/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The ark-commenteditor WordPress plugin up to and including 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing malicious users to inject an iFrame in the page and thus load arbitrary content from any page to the comment section

Vulnerable Product Search on Vulmon Subscribe to Product

obg ark wysiwyg comment editor