Favicon by RealFaviconGenerator <= 1.3.46 - Unauthenticated Stored Cross-Site Scripting
high
The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.3.46 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 7.2
- Affected:
- up to 1.3.46
- Fixed in:
- 1.3.47
- Disclosed:
- May 30, 2026
CVE-2026-42754 on NVD →
Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.3.30
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Philippe Bernard Favicon.This issue affects Favicon: from n/a through 1.3.29.
- Affected:
- up to 1.3.30
- Fixed in:
- 1.3.30
- Disclosed:
- Apr 15, 2024
CVE-2024-31422 on NVD →
Favicon <= 1.3.29 - Cross-Site Request Forgery to Notice Dismissal
medium
The Favicon plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.29. This is due to missing or incorrect nonce validation on the process_ignored_notice() function. This makes it possible for unauthenticated attackers to dismiss notices via a forged request granted they...
- CVSS:
- 4.3
- Affected:
- up to 1.3.29
- Fixed in:
- 1.3.30
- Disclosed:
- Apr 10, 2024
CVE-2024-31422 on NVD →
Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.2.13
unknown
[en] A vulnerability classified as problematic has been found in RealFaviconGenerator Favicon Plugin up to 1.2.12 on WordPress. This affects the function install_new_favicon of the file admin/class-favicon-by-realfavicongenerator-admin.php. The manipulation leads to cross-site request forgery. It is possible to initiat...
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
- Disclosed:
- Jun 6, 2023
CVE-2015-10116 on NVD →
Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.3.23
unknown
[en] The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 1.3.23
- Fixed in:
- 1.3.23
- Disclosed:
- Apr 11, 2022
CVE-2022-0471 on NVD →
Favicon by RealFaviconGenerator <= 1.3.22 - Reflected Cross-Site Scripting
medium
The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 1.3.23
- Fixed in:
- 1.3.23
- Disclosed:
- Mar 21, 2022
CVE-2022-0471 on NVD →
Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.3.22
unknown
[en] The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.
- Affected:
- up to 1.3.22
- Fixed in:
- 1.3.22
- Disclosed:
- Aug 30, 2021
CVE-2021-24437 on NVD →
Favicon by RealFaviconGenerator <= 1.3.21 - Reflected Cross-Site Scripting
medium
The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.
- CVSS:
- 6.1
- Affected:
- up to 1.3.21
- Fixed in:
- 1.3.21
- Disclosed:
- Jul 27, 2021
CVE-2021-24437 on NVD →
Favicon by RealFaviconGenerator <= 1.2.12 - Reflected Cross-Site Scripting
high
The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘json_result_url’ parameter in versions before 1.2.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 7.1
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
- Disclosed:
- Apr 1, 2015
CVE-2015-10116 on NVD →
Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.2.13
unknown
Because of this vulnerability, attackers can trick the authenticated administrator of a WordPress site to download and install a faked favicon package.
Update the plugin.
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
- Disclosed:
- Apr 1, 2015
Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.2.13
unknown
The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘json_result_url’ parameter in versions before 1.2.13 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
- Disclosed:
- Apr 1, 2015
Favicon by RealFaviconGenerator [favicon-by-realfavicongenerator] < 1.2.13
unknown
The Favicon by RealFaviconGenerator WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database