vendor:
All In One Favicon
by:
Javier Olmedo
8.8
CVSS
HIGH
Authenticated Multiple XSS Persistent
79
CWE
Product Name: All In One Favicon
Affected Version From: 4.6 and below
Affected Version To: unpatched
Patch Exists: YES
Related CWE: 2018-13832
CPE: a:techotronic:all_in_one_favicon
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WordPress
2018
WordPress Plugin All In One Favicon <= 4.6 - Authenticated Multiple XSS Persistent
WordPress Plugin All In One Favicon before 4.6 allows remote authenticated users to execute javascript code through XSS Persistent attacks. The following parameters are vulnerable: backendApple-Text, backendICO-Text, backendPNG-Text, backendGIF-Text, frontendApple-Text, frontendICO-Text, frontendPNG-Text, frontendGIF-Text.
Mitigation:
Update to the latest version of the plugin.