The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section
Metrics
Affected Vendors & Products
References
History
Mon, 02 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2024-01-16T15:52:25.423Z
Updated: 2025-06-02T15:10:29.086Z
Reserved: 2022-04-29T09:30:03.602Z
Link: CVE-2021-4227

Updated: 2024-08-03T17:23:08.904Z

Status : Modified
Published: 2024-01-16T16:15:09.270
Modified: 2025-06-02T16:15:23.187
Link: CVE-2021-4227

No data.