Vulnerabilities and security researches forinsert-or-embed-articulate-content-into-wordpress insert-or-embed-articulate-content-into-wordpress
Direction: descendingApr 12, 2025
Insert or Embed Articulate Content into WordPress # CVE-2025-32202
- CVE, Research URL
- Date
- Apr 10, 2025
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress allows Upload a Web Shell to a Web Server. This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000025.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Nov 15, 2024
Insert or Embed Articulate Content into WordPress # CVE-2022-4974
- CVE, Research URL
- Date
- Oct 16, 2024
- Research Description
- The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jul 22, 2024
Insert or Embed Articulate Content into WordPress # CVE-2024-0756
- CVE, Research URL
- Date
- Jun 04, 2024
- Research Description
- The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jul 18, 2024
Insert or Embed Articulate Content into WordPress # CVE-2024-5630
- CVE, Research URL
- Date
- Jul 15, 2024
- Research Description
- The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 10, 2024
Insert or Embed Articulate Content into WordPress # CVE-2024-0757
- CVE, Research URL
- Date
- Jun 04, 2024
- Research Description
- The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Insert or Embed Articulate Content into WordPress # CVE-2019-15648
- CVE, Research URL
- Date
- Aug 27, 2019
- Research Description
- The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Insert or Embed Articulate Content into WordPress # CVE-2023-50824
- CVE, Research URL
- Date
- Dec 21, 2023
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable
Jun 06, 2024
Insert or Embed Articulate Content into WordPress # CVE-2019-15649
- CVE, Research URL
- Date
- Aug 27, 2019
- Research Description
- The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.
- Affected versions
-
Min -, max -.
- Status
-
vulnerable