The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/6ce62e78-04a4-46b2-b97f-c4ef8f3258c3/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-09-13 06:15
Updated : 2024-09-27 21:26
NVD link : CVE-2024-7864
Mitre link : CVE-2024-7864
CVE.ORG link : CVE-2024-7864
JSON object : View
Products Affected
pixeljar
- favicon_generator
CWE
CWE-352
Cross-Site Request Forgery (CSRF)