CVE-2021-24437

CVE-2021-24437: Favicon by RealFaviconGenerator <= 1.3.20 - Reflected Cross-Site Scripting (XSS)

Vendor Unknown
Product Favicon by RealFaviconGenerator
Weakness CWE-79 · XSS
Published August 30, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.

Key dates

02Disclosure timeline

August 30, 2021 CVE published
August 3, 2024 Record updated