Input validation vulnerability in WP Font Awesome 1.7.9

The WP Font Awesome plugin for WordPress is vulnerable to a security issue. This issue allows attackers with contributor-level permissions or higher to add malicious code to certain pages. This malicious code will execute whenever an unsuspecting user visits the page. The vulnerability was present in versions of the plugin up to, and including, 1.7.9. It was caused by a lack of input sanitization and output escaping on the ‘icon’ user supplied attribute.

Detected in:

WP Font Awesome open vulnerable versions: >= * <= 1.7.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.