What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in SedLex FavIcon Switcher plugin <= 1.2.11 at WordPress allows plugin settings change.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in SedLex FavIcon Switcher plugin <= 1.2.11 at WordPress allows plugin settings change.
Explanation of Vulnerability in Simple Terms
The FavIcon Switcher WordPress plugin through version 1.2.11 does not properly validate requests, allowing authenticated users to modify plugin settings without explicit confirmation. An attacker with low-level access can change the site's favicon or other settings via forged requests. The vulnerability requires an authenticated account but no additional user interaction from the victim.
What an attacker can do
Modify plugin settings like the site favicon without the site owner's knowledge or consent.
Potential impact on your site
Unauthorized changes to your site's favicon or other FavIcon Switcher settings by any logged-in user.
Conditions required to exploit
Attacker must have a low-privilege WordPress account (subscriber or higher); no victim interaction needed.
Key dates
External resources
Related vulnerabilities