WordPress security by component
Favicon
Plugin description
Favicon is a WordPress component with 5 published CVE records in this archive. The latest tracked vulnerability was published May 27, 2026; the highest CVE/CNA score is 7.1.
Plugin slug:
favicon-by-realfavicongeneratorLatest vulnerability
CVE-2026-42754: Favicon: Cross-site scripting
Favicon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.3.46.
| Safe version |
|
||
|---|---|---|---|
| May 27, 2026 |
CVE-2026-42754
Favicon: Cross-site scripting
Favicon is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.3.46.
|
1.3.47 |
CVE7.1
NVDPending
|
| Apr 15, 2024 |
CVE-2024-31422
Favicon: Cross-site request forgery
Favicon is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Jun 06, 2023 |
CVE-2015-10116
Favicon By Realfavicongenerator: Cross-site request forgery
Favicon By Realfavicongenerator is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| Apr 11, 2022 |
CVE-2022-0471
Favicon by RealFaviconGenerator: Cross-site scripting
Favicon by RealFaviconGenerator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 30, 2021 |
CVE-2021-24437
Favicon by RealFaviconGenerator: Cross-site scripting
Favicon by RealFaviconGenerator is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|