Vulnerabilities and security researches forfont-awesome font-awesome
Direction: descendingJun 25, 2026
Font Awesome # PSC-2026-64668
- PSC, Research URL
- Home page URL
- Application
- Date
- Jun 25, 2026
- Research Description
- Icon plugins affect the editor, public markup, scripts, styles, and sometimes external kit configuration. That makes them convenient for visual design, but also security-sensitive because stored icon settings and asset URLs can become part of the public HTML served to visitors. Font Awesome version 5.1.5 has successfully completed the CleanTalk Plugin Security Certification process and received PSC-2026-64668, confirming that the plugin was reviewed from a secure code perspective with attention to common exploitation paths for icon rendering, asset loading, kit configuration, and editor integration behavior.
- Affected versions
-
Min 5.1.5, max 5.1.5.
- Status
-
SAFE & CERTIFIED
Jun 16, 2026
Font Awesome # 1f92541a-c18c-4e76-948a-9c954fc5bd59
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Font Awesome [font-awesome] >= 4.0.0-rc15 - <= 4.0.0-rc16 Font Awesome 4.0.0-RC15 & RC16 - API Token & Access Token Disclosure The vulnerability exposes the Font Awesome API token and access token for users who have configured the plugin to use a kit. If compromised, these tokens could give an unauthorized person access to that user’s list of kits and kit settings.
- Affected versions
-
Min 4.0.0-rc15, max 4.0.0-rc16.
- Status
-
vulnerable
Font Awesome # c7c83cad06dd49b30f023f84c2fcfaf603bb8ef0
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 11, 2020
- Research Description
- Font Awesome [font-awesome] >= 4.0.0-rc15 - <= 4.0.0-rc16 Font Awesome 4.0.0-rc15 and 4.0.0-rc16 - API Token Exposure The Font Awesome plugin for WordPress versions 4.0.0-rc15 and 4.0.0-rc16 are vulnerable to API Token Exposure. The vulnerability exposes the Font Awesome API token and access token for users who have configured the plugin to use a kit. If compromised, these tokens could give an unauthorized person access to that user’s list of kits and kit settings.
- Affected versions
-
Min 4.0.0-rc15, max 4.0.0-rc16.
- Status
-
vulnerable
Jun 06, 2024
Font Awesome # CVE-2022-4478
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 16, 2023
- Research Description
- The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.
- Affected versions
-
Min 4.0.0-rc15, max 4.3.2.
- Status
-
vulnerable
Font Awesome # 3a8ac41100c64e1a87eb12ac70f52fa81a30ec32
- CVE, Research URL
- Home page URL
- Application
- Date
- Mar 11, 2020
- Research Description
- Font Awesome [font-awesome] >= 4.0.0-RC15 - <= 4.0.0-RC16 WordPress Font Awesome plugin 4.0.0-RC15 - 4.0.0-RC16 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress Font Awesome plugin (versions 4.0.0-RC15 - 4.0.0-RC16).
- Affected versions
-
Min 4.0.0-RC15, max 4.0.0-RC16.
- Status
-
vulnerable