CVE-2022-40219 MEDIUM

CVE-2022-40219: WordPress FavIcon Switcher plugin <= 1.2.11 - Cross-Site Request Forgery (CSRF) vulnerability

Vendor Sedlex
Product FavIcon Switcher (WordPress plugin)
Weakness CWE-352 · CSRF
Published September 21, 2022
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Cross-Site Request Forgery (CSRF) vulnerability in SedLex FavIcon Switcher plugin <= 1.2.11 at WordPress allows plugin settings change.

Explanation of Vulnerability in Simple Terms

02Summary

The FavIcon Switcher WordPress plugin through version 1.2.11 does not properly validate requests, allowing authenticated users to modify plugin settings without explicit confirmation. An attacker with low-level access can change the site's favicon or other settings via forged requests. The vulnerability requires an authenticated account but no additional user interaction from the victim.

What an attacker can do

03Attacker Capabilities

Modify plugin settings like the site favicon without the site owner's knowledge or consent.

Potential impact on your site

04Site Impact

Unauthorized changes to your site's favicon or other FavIcon Switcher settings by any logged-in user.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege WordPress account (subscriber or higher); no victim interaction needed.

Key dates

06Disclosure timeline

September 21, 2022 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE