Input validation vulnerability in Favicon by RealFaviconGenerator 1.2.13

The Favicon by RealFaviconGenerator plugin for WordPress is vulnerable to a security risk called Reflected Cross-Site Scripting in versions before 1.2.13. This risk can be exploited by an unauthenticated attacker who can trick a user into performing an action, such as clicking on a link. This action can inject malicious web scripts into pages, which can be executed by the user. To protect against this risk, users should make sure they are using the most up to date version of the plugin.

Detected in:

Favicon by RealFaviconGenerator fixed vulnerable versions: >= * < 1.2.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.