PT-2024-38640 · WordPress · The Favicon Generator

Daniel Ruf

·

Published

2024-09-12

·

Updated

2024-09-27

·

CVE-2024-7863

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions The Favicon Generator (CLOSED) WordPress plugin versions prior to 2.1
Description The issue concerns a lack of file validation for uploads and missing CSRF checks. This could allow attackers to make logged-in admins upload arbitrary files, such as PHP files, to the server.
Recommendations For versions prior to 2.1, update to version 2.1 or later to resolve the issue. As a temporary workaround, consider restricting file upload capabilities to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-7863

Affected Products

The Favicon Generator