{"error":0,"message":null,"data":{"name":"Font Awesome","plugin":"font-awesome","link":"https:\/\/wordpress.org\/plugins\/font-awesome\/","latest":"1786656300","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"349add53ecdf3a63cd308cac500c9b894aa9504ce880cc24b45f2f82b7bc8258","name":"Font Awesome [font-awesome] >= 4.0.0-RC15 - <= 4.0.0-RC16","description":null,"operator":{"min_version":"4.0.0-RC15","min_operator":"ge","max_version":"4.0.0-RC16","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"3a8ac41100c64e1a87eb12ac70f52fa81a30ec32","name":"WordPress Font Awesome plugin 4.0.0-RC15 - 4.0.0-RC16 - Sensitive Information Disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/font-awesome\/vulnerability\/wordpress-font-awesome-plugin-4-0-0-rc15-4-0-0-rc16-sensitive-information-disclosure-vulnerability","description":"Sensitive Information Disclosure vulnerability discovered in WordPress Font Awesome plugin (versions 4.0.0-RC15 - 4.0.0-RC16).","date":"2020-03-11"}],"impact":[]},{"uuid":"6619e3a6d3c1b7299c665137029eed668cebdb042411cef7ab965df285ea7e18","name":"Font Awesome [font-awesome] >= 4.0.0-rc15 - <= 4.0.0-rc16","description":null,"operator":{"min_version":"4.0.0-rc15","min_operator":"ge","max_version":"4.0.0-rc16","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"c7c83cad06dd49b30f023f84c2fcfaf603bb8ef0","name":"Font Awesome 4.0.0-rc15 and 4.0.0-rc16 - API Token Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/font-awesome\/font-awesome-400-rc15-and-400-rc16-api-token-exposure","description":"The Font Awesome plugin for WordPress versions 4.0.0-rc15 and 4.0.0-rc16 are vulnerable to API Token Exposure. The vulnerability exposes the Font Awesome API token and access token for users who have configured the plugin to use a kit. If compromised, these tokens could give an unauthorized person access to that user\u2019s list of kits and kit settings.","date":"2020-03-11"}],"impact":[]},{"uuid":"ac9b6356d98cdf4cda43d7262e097990f11f55c070ebf5f08eb625b46f0c3f8a","name":"Font Awesome [font-awesome] < 4.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-4478","name":"CVE-2022-4478","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-4478","description":"[en] The Font Awesome WordPress plugin before 4.3.2 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.","date":"2023-01-16"},{"id":"53bb33b3e3b47dbd2f5c29c65837b6b581f7757c","name":"WordPress  Font Awesome Plugin  < 4.3.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/font-awesome\/vulnerability\/wordpress-font-awesome-plugin-4-3-2-contributor-stored-xss-vulnerability","description":"Update the WordPress Font Awesome plugin to the latest available version (at least 4.3.2).\nLana Codes discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Font Awesome Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 4.3.2.","date":"2022-12-22"},{"id":"35bd0d011c513a3824251fdac3bdf0ffd9919f15","name":"Font Awesome <= 4.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/font-awesome\/font-awesome-431-authenticated-contributor-stored-cross-site-scripting-via-shortcode","description":"The Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode in versions up to, and including, 4.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2022-12-22"},{"id":"4de75de5-e557-46df-9675-e3f0220f4003","name":"Font Awesome &lt; 4.3.2 - Contributor+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/4de75de5-e557-46df-9675-e3f0220f4003","description":"The plugin does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f406676c170215387a3df6baeef3bffd309a5af3dbc94bc5efa1ef168ccfef78","name":"Font Awesome [font-awesome] >= 4.0.0-rc15 - <= 4.0.0-rc16","description":null,"operator":{"min_version":"4.0.0-rc15","min_operator":"ge","max_version":"4.0.0-rc16","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"1f92541a-c18c-4e76-948a-9c954fc5bd59","name":"Font Awesome 4.0.0-RC15 &amp; RC16 - API Token &amp; Access Token Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/1f92541a-c18c-4e76-948a-9c954fc5bd59","description":"The vulnerability exposes the Font Awesome API token and access token for users who have configured the plugin to use a kit. If compromised, these tokens could give an unauthorized person access to that user&rsquo;s list of kits and kit settings.","date":null}],"impact":[]}]},"updated":"1776153795"}