Impact
The Favicon plugin by phbernard contains an improper neutralization of input during web page generation, which leads to a reflected Cross‑Site Scripting flaw. The vulnerability occurs when an attacker supplies crafted parameters that are echoed into the browser’s rendering context without appropriate escaping. If exploited, a malicious actor could inject arbitrary JavaScript into the victim’s browser, enabling cookie theft, session hijacking, or the execution of arbitrary scripts on the site. The weakness is identified as CWE‑79, a client‑side injection issue.
Affected Systems
Any WordPress website installing the Favicon plugin the version numbers up to and including 1.3.46 is susceptible. The plugin is distributed as "phbernard: Favicon" and no version range beyond 1.3.46 is indicated as affected.
Risk and Exploitability
The CVSS Base score of 7.1 reflects a medium‑high severity for an XSS vulnerability that does not require authentication. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based, via a specially crafted URL or form input that the plugin reflects back in the page. Because the flaw is client‑side, no privileged privileges are needed by the attacker, and exploitation can be performed by any user visiting a malicious link.
OpenCVE Enrichment