Description
Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon personal-favicon allows Stored XSS.This issue affects Personal Favicon: from n/a through <= 2.0.
Published: 2025-06-06
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to perform a cross‑site request forgery that injects a malicious script into the plugin’s stored data. When a legitimate admin or user views the site, the injected script executes in the victim’s browser. This can lead to defacement, theft of session cookies, or other malicious actions originating from the site. The weakness is identified as a Stored Cross‑Site Scripting flaw (CWE‑352 for the CSRF component).

Affected Systems

The issue impacts the Personal Favicon plugin by mangup on WordPress installations. All releases from the initial build up through version 2.0 are vulnerable; no specific sub‑version range is provided. Users should verify the plugin version and plan for an upgrade if it falls within this range.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a CSRF request crafted by an attacker, which a privileged or authenticated user unknowingly submits. If the attacker can persuade a site administrator or logged‑in user to visit a malicious link, they can store the payload for all visitors. The risk is therefore moderate, provided the site has a mix of administrators and external users who may be exposed to the stored script.

Generated by OpenCVE AI on May 1, 2026 at 07:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Personal Favicon to a version newer than 2.0
  • If an upgrade is not possible, deactivate or uninstall the plugin to eliminate the attack surface
  • Apply site‑wide access controls so that only trusted administrators can submit configuration data to the plugin

Generated by OpenCVE AI on May 1, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17171 Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon allows Stored XSS. This issue affects Personal Favicon: from n/a through 2.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon allows Stored XSS. This issue affects Personal Favicon: from n/a through 2.0. Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon personal-favicon allows Stored XSS.This issue affects Personal Favicon: from n/a through <= 2.0.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Fri, 06 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in mangup Personal Favicon allows Stored XSS. This issue affects Personal Favicon: from n/a through 2.0.
Title WordPress Personal Favicon plugin <= 2.0 - CSRF to Stored XSS vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:51.901Z

Reserved: 2025-03-11T08:10:19.510Z

Link: CVE-2025-28964

cve-icon Vulnrichment

Updated: 2025-06-06T15:01:12.304Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:28.513

Modified: 2026-06-17T09:04:57.957

Link: CVE-2025-28964

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T08:00:13Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)