CVE Database
/

CVE-2024-7864

Back to search

CVE-2024-7864

Published: Sep 13, 2024

Modified: Sep 13, 2024

PUBLISHED

Description

The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server

VendorProductVersions

Unknown

Favicon Generator (CLOSED)

affected
0 - < 2.1

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now