ZeroHour

CVE-2024-7863

PoC
CVSS 3.1
6.8 medium
EPSS
<1%p22
Published
()
Modified
Description

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server

Vendors
pixeljar
Products
favicon generator
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.