cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forinsert-or-embed-articulate-content-into-wordpress insert-or-embed-articulate-content-into-wordpress

Direction: descending
Apr 12, 2025

Insert or Embed Articulate Content into WordPress # CVE-2025-32202

CVE, Research URL

CVE-2025-32202

Date
Apr 10, 2025
Research Description
Unrestricted Upload of File with Dangerous Type vulnerability in Brian Batt - elearningfreak.com Insert or Embed Articulate Content into WordPress allows Upload a Web Shell to a Web Server. This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000025.
Affected versions
Min -, max -.
Status
vulnerable
Nov 15, 2024

Insert or Embed Articulate Content into WordPress # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
Min -, max -.
Status
vulnerable
Jul 22, 2024

Insert or Embed Articulate Content into WordPress # CVE-2024-0756

CVE, Research URL

CVE-2024-0756

Date
Jun 04, 2024
Research Description
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding iframes, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page.
Affected versions
Min -, max -.
Status
vulnerable
Jul 18, 2024

Insert or Embed Articulate Content into WordPress # CVE-2024-5630

CVE, Research URL

CVE-2024-5630

Date
Jul 15, 2024
Research Description
The Insert or Embed Articulate Content into WordPress plugin before 4.3000000024 does not prevent authors from uploading arbitrary files to the site, which may allow them to upload PHP shells on affected sites.
Affected versions
Min -, max -.
Status
vulnerable
Jun 10, 2024

Insert or Embed Articulate Content into WordPress # CVE-2024-0757

CVE, Research URL

CVE-2024-0757

Date
Jun 04, 2024
Research Description
The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files
Affected versions
Min -, max -.
Status
vulnerable

Insert or Embed Articulate Content into WordPress # CVE-2019-15648

CVE, Research URL

CVE-2019-15648

Date
Aug 27, 2019
Research Description
The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber.
Affected versions
Min -, max -.
Status
vulnerable

Insert or Embed Articulate Content into WordPress # CVE-2023-50824

CVE, Research URL

CVE-2023-50824

Date
Dec 21, 2023
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Batt Insert or Embed Articulate Content into WordPress allows Stored XSS.This issue affects Insert or Embed Articulate Content into WordPress: from n/a through 4.3000000021.
Affected versions
Min -, max -.
Status
vulnerable
Jun 06, 2024

Insert or Embed Articulate Content into WordPress # CVE-2019-15649

CVE, Research URL

CVE-2019-15649

Date
Aug 27, 2019
Research Description
The insert-or-embed-articulate-content-into-wordpress plugin before 4.2999 for WordPress has insufficient restrictions on file upload.
Affected versions
Min -, max -.
Status
vulnerable