plugin

Favicon By Realfavicongenerator Vulnerabilities

12 known security issues reported for the Favicon By Realfavicongenerator WordPress plugin. Most recent disclosed May 30, 2026.

2 high 3 medium

Running Favicon By Realfavicongenerator on your site? Check whether your installed version is affected.

Scan your site free

Favicon by RealFaviconGenerator <= 1.3.46 - Unauthenticated Stored Cross-Site Scripting

high

The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...

CVSS:
7.2
Affected:
up to 1.3.46
Fixed in:
1.3.47
Disclosed:
May 30, 2026

CVE-2026-42754 on NVD →

Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.3.30

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Philippe Bernard Favicon.This issue affects Favicon: from n/a through 1.3.29.

Affected:
up to 1.3.30
Fixed in:
1.3.30
Disclosed:
Apr 15, 2024

CVE-2024-31422 on NVD →

Favicon <= 1.3.29 - Cross-Site Request Forgery to Notice Dismissal

medium

The Favicon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.29. This is due to missing or incorrect nonce validation on the process_ignored_notice() function. This makes it possible for unauthenticated attackers to dismiss notices via a forged request granted they...

CVSS:
4.3
Affected:
up to 1.3.29
Fixed in:
1.3.30
Disclosed:
Apr 10, 2024

CVE-2024-31422 on NVD →

Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.2.13

unknown

[en] A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function install_new_favicon of the file admin/class-favicon-by-realfavicongenerator-admin.php. The manipulation leads to cross-site request forgery. It is possible to initiat...

Affected:
up to 1.2.13
Fixed in:
1.2.13
Disclosed:
Jun 6, 2023

CVE-2015-10116 on NVD →

Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.3.23

unknown

[en] The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 1.3.23
Fixed in:
1.3.23
Disclosed:
Apr 11, 2022

CVE-2022-0471 on NVD →

Favicon by RealFaviconGenerator <= 1.3.22 - Reflected Cross-Site Scripting

medium

The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 1.3.23
Fixed in:
1.3.23
Disclosed:
Mar 21, 2022

CVE-2022-0471 on NVD →

Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.3.22

unknown

[en] The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.

Affected:
up to 1.3.22
Fixed in:
1.3.22
Disclosed:
Aug 30, 2021

CVE-2021-24437 on NVD →

Favicon by RealFaviconGenerator <= 1.3.21 - Reflected Cross-Site Scripting

medium

The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.

CVSS:
6.1
Affected:
up to 1.3.21
Fixed in:
1.3.21
Disclosed:
Jul 27, 2021

CVE-2021-24437 on NVD →

Favicon by RealFaviconGenerator <= 1.2.12 - Reflected Cross-Site Scripting

high

The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘json_result_url’ parameter in versions before 1.2.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

CVSS:
7.1
Affected:
up to 1.2.13
Fixed in:
1.2.13
Disclosed:
Apr 1, 2015

CVE-2015-10116 on NVD →

Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.2.13

unknown

Because of this vulnerability, attackers can trick the authenticated administrator of a WordPress site to download and install a faked favicon package. Update the plugin.

Affected:
up to 1.2.13
Fixed in:
1.2.13
Disclosed:
Apr 1, 2015

Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.2.13

unknown

The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘json_result_url’ parameter in versions before 1.2.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...

Affected:
up to 1.2.13
Fixed in:
1.2.13
Disclosed:
Apr 1, 2015

Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.2.13

unknown

The Favicon by RealFaviconGenerator WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 1.2.13
Fixed in:
1.2.13

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database