Known vulnerabilities in Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg)
Embed secure, responsive iFrames in WordPress with Elementor or Gutenberg. Supports lazy loading, auto-height, and dynamic URLs. No coding required.
1Reported vulnerabilities
6.4Highest CVSS score
2.0.3Latest version
4,000+Active installs
What to do now
Update Custom iFrame – Embed PDFs, Videos, and External Content in WordPress (Elementor & Gutenberg) to 1.0.14 or later.
1 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-59553 | Medium | 0.2% | 1.0.13 and earlier | 1.0.14 |
September 22, 2025 |