Sceawere

Vulnerability Detail

CVE-2026-5725UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Favicon Rotator Reflected XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
archetyped
Product
Favicon Rotator
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fvrt_' prefixed request parameters in all versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-10T07:16:41.650Z",
  "pubdate": "2026-10-10T07:16:41.650Z",
  "executiveSummary": "The Favicon Rotator plugin for WordPress, in all versions up to and including 1.2.11, is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw stems from the improper sanitization and escaping of user-supplied input provided through 'fvrt_' prefixed request parameters.\nThe vulnerability permits an unauthenticated attacker to inject malicious JavaScript into the rendered web page, which executes within the context of the victim's browser session. By tricking an authenticated user—such as an administrator—into interacting with a crafted URL, an attacker can execute arbitrary scripts, potentially leading to unauthorized actions, session hijacking, or the exfiltration of sensitive information.\nGiven that the attack requires no authentication and relies on user interaction to facilitate the reflected payload, the risk remains significant for sites utilizing the affected plugin version. Administrators should treat this as a high-priority concern due to the potential for complete compromise of the victim's session integrity.",
  "technicalDetails": "The vulnerability resides in the way the Favicon Rotator plugin handles HTTP request parameters prefixed with 'fvrt_'. The application processes these inputs and reflects them directly into the HTML response without adequate sanitization or output encoding. This creates a classic Reflected XSS condition where the server-side code fails to validate or sanitize inputs before rendering them back to the end-user's browser.\nThe root cause is the absence of secure output encoding mechanisms, such as those provided by the WordPress esc_html() or esc_url() functions, when handling the 'fvrt_' parameters. When a request containing malicious JavaScript within these parameters is processed, the browser interprets the input as legitimate executable content rather than plain text.\nThe attack flow begins when an attacker crafts a malicious URL containing a payload within one of the vulnerable 'fvrt_' parameters. This payload typically consists of an HTML script tag or an event-based JavaScript handler, such as 'onerror' or 'onload'. The attacker then distributes this link to a target user, often via phishing or social engineering. Once the target clicks the link, the server receives the request, processes the malicious parameter, and reflects the payload back into the page response.\nUpon receiving the malicious response, the victim's browser executes the injected script within the current security context of the WordPress site. Because the execution occurs in the victim's browser, the attacker can leverage the victim's session tokens to perform unauthorized administrative actions, modify plugin settings, or capture sensitive cookies. The lack of authentication requirements allows any remote, unauthenticated attacker to initiate the request, provided they can successfully coerce a target into clicking the malicious link.\nThe impact is significant, as successful exploitation enables the attacker to perform actions on behalf of the user, potentially escalating to full site compromise if the target possesses high-level privileges. Since the vulnerability affects all versions through 1.2.11, all deployments are currently exposed if they remain unpatched."
}
CVE-2026-5725: Favicon Rotator Reflected XSS (MEDIUM Severity, CVSS: 6.1) | Sceawere