Vulnerabilities (CVE)

Filtered by vendor Genie Wp Favicon Project Subscribe
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24674 1 Genie Wp Favicon Project 1 Genie Wp Favicon 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack