4.8
CVSSv3

CVE-2018-13832

Published: 16/07/2018 Updated: 13/09/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote malicious users to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

techotronic all in one favicon

Exploits

# Exploit Title: WordPress Plugin All In One Favicon <= 46 - Authenticated Multiple XSS Persistent # Date: 2018-07-10 # Exploit Author: Javier Olmedo # Website: hackpuntescom/ # Vendor Homepage: wwwtechotronicde/ # Software Link: wordpressorg/plugins/all-in-one-favicon/ # Version/s: 46 and below # Patched Version: ...
WordPress All In One Favicon plugin version 46 suffers from a cross site scripting vulnerability ...