What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arne Franken All In One Favicon.This issue affects All In One Favicon: from n/a through 4.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arne Franken All In One Favicon.This issue affects All In One Favicon: from n/a through 4.7.
Explanation of Vulnerability in Simple Terms
All In One Favicon versions 4.7 and earlier contain a path traversal vulnerability that allows high-privilege users to cause a denial of service by manipulating file paths. An attacker with administrative access can trigger the vulnerability to make the site unavailable. The scope is changed, meaning the impact extends beyond the plugin itself.
What an attacker can do
Make the site unavailable (denial of service) by manipulating file paths.
Potential impact on your site
An admin account compromise could render your site unavailable until the plugin is disabled or updated.
Conditions required to exploit
Attacker must have high-level administrative privileges on the WordPress site.
Key dates
External resources
Related vulnerabilities