CVE Database
/

CVE-2021-4227

Back to search

CVE-2021-4227

Published: Jan 16, 2024

Modified: Jun 2, 2025

PUBLISHED

Description

The ark-commenteditor WordPress plugin through 2.15.6 does not properly sanitise or encode the comments when in Source editor, allowing attackers to inject an iFrame in the page and thus load arbitrary content from any page to the comment section

VendorProductVersions

Unknown

ark-commenteditor

affected
0 - <= 2.15.6

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now