All In One Favicon [all-in-one-favicon] < 4.8
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arne Franken All In One Favicon.This issue affects All In One Favicon: from n/a through 4.7.
- Affected:
- up to 4.8
- Fixed in:
- 4.8
- Disclosed:
- Feb 23, 2024
CVE-2023-24416 on NVD →
All In One Favicon <= 4.7 - Authenticated(Admin+) Directory Traversal
medium
All In One Favicon plugin for WordPress is vulnerable to Directory Traversal via the 'aioFaviconUpdateSettings' function in versions up to, and including, 4.7. This allows authenticated attackers with administator-level permissions to delete arbitrary files on the site.
- CVSS:
- 6.5
- Affected:
- up to 4.7
- Fixed in:
- 4.8
- Disclosed:
- Feb 23, 2023
CVE-2023-24416 on NVD →
All In One Favicon [all-in-one-favicon] < 4.7
unknown
[en] Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.
- Affected:
- up to 4.7
- Fixed in:
- 4.7
- Disclosed:
- Jul 16, 2018
CVE-2018-13832 on NVD →
All In One Favicon <= 4.6 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.
- CVSS:
- 5.5
- Affected:
- up to 4.6
- Fixed in:
- 4.7
- Disclosed:
- Jul 10, 2018
CVE-2018-13832 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database