plugin

All In One Favicon Vulnerabilities

4 known security issues reported for the All In One Favicon WordPress plugin. Most recent disclosed Feb 23, 2024.

2 medium

Running All In One Favicon on your site? Check whether your installed version is affected.

Scan your site free

All In One Favicon [all-in-one-favicon] < 4.8

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arne Franken All In One Favicon.This issue affects All In One Favicon: from n/a through 4.7.

Affected:
up to 4.8
Fixed in:
4.8
Disclosed:
Feb 23, 2024

CVE-2023-24416 on NVD →

All In One Favicon <= 4.7 - Authenticated(Admin+) Directory Traversal

medium

All In One Favicon plugin for WordPress is vulnerable to Directory Traversal via the 'aioFaviconUpdateSettings' function in versions up to, and including, 4.7. This allows authenticated attackers with administator-level permissions to delete arbitrary files on the site.

CVSS:
6.5
Affected:
up to 4.7
Fixed in:
4.8
Disclosed:
Feb 23, 2023

CVE-2023-24416 on NVD →

All In One Favicon [all-in-one-favicon] < 4.7

unknown

[en] Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.

Affected:
up to 4.7
Fixed in:
4.7
Disclosed:
Jul 16, 2018

CVE-2018-13832 on NVD →

All In One Favicon <= 4.6 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.

CVSS:
5.5
Affected:
up to 4.6
Fixed in:
4.7
Disclosed:
Jul 10, 2018

CVE-2018-13832 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database