cleantalk
Vulnerabilities and Security Researches

Favicon Generator, CVE-2024-7864

CVE, Research URL

CVE-2024-7864

Application

Favicon Generator

Published on
Sep 13, 2024
Research Description
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server
Affected versions
max 2.1.
Status
vulnerable