Sceawere
Vulnerability Detail
CVE-2026-5725UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Favicon Rotator Reflected XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.1
- Creation Date
- 3h ago
- Vendor
- archetyped
- Product
- Favicon Rotator
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Favicon Rotator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fvrt_' prefixed request parameters in all versions up to, and including, 1.2.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.1",
"pubDate": "2026-10-10T07:16:41.650Z",
"pubdate": "2026-10-10T07:16:41.650Z",
"executiveSummary": "The Favicon Rotator plugin for WordPress, in all versions up to and including 1.2.11, is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability. This security flaw stems from the improper sanitization and escaping of user-supplied input provided through 'fvrt_' prefixed request parameters.\nThe vulnerability permits an unauthenticated attacker to inject malicious JavaScript into the rendered web page, which executes within the context of the victim's browser session. By tricking an authenticated user—such as an administrator—into interacting with a crafted URL, an attacker can execute arbitrary scripts, potentially leading to unauthorized actions, session hijacking, or the exfiltration of sensitive information.\nGiven that the attack requires no authentication and relies on user interaction to facilitate the reflected payload, the risk remains significant for sites utilizing the affected plugin version. Administrators should treat this as a high-priority concern due to the potential for complete compromise of the victim's session integrity.",
"technicalDetails": "The vulnerability resides in the way the Favicon Rotator plugin handles HTTP request parameters prefixed with 'fvrt_'. The application processes these inputs and reflects them directly into the HTML response without adequate sanitization or output encoding. This creates a classic Reflected XSS condition where the server-side code fails to validate or sanitize inputs before rendering them back to the end-user's browser.\nThe root cause is the absence of secure output encoding mechanisms, such as those provided by the WordPress esc_html() or esc_url() functions, when handling the 'fvrt_' parameters. When a request containing malicious JavaScript within these parameters is processed, the browser interprets the input as legitimate executable content rather than plain text.\nThe attack flow begins when an attacker crafts a malicious URL containing a payload within one of the vulnerable 'fvrt_' parameters. This payload typically consists of an HTML script tag or an event-based JavaScript handler, such as 'onerror' or 'onload'. The attacker then distributes this link to a target user, often via phishing or social engineering. Once the target clicks the link, the server receives the request, processes the malicious parameter, and reflects the payload back into the page response.\nUpon receiving the malicious response, the victim's browser executes the injected script within the current security context of the WordPress site. Because the execution occurs in the victim's browser, the attacker can leverage the victim's session tokens to perform unauthorized administrative actions, modify plugin settings, or capture sensitive cookies. The lack of authentication requirements allows any remote, unauthenticated attacker to initiate the request, provided they can successfully coerce a target into clicking the malicious link.\nThe impact is significant, as successful exploitation enables the attacker to perform actions on behalf of the user, potentially escalating to full site compromise if the target possesses high-level privileges. Since the vulnerability affects all versions through 1.2.11, all deployments are currently exposed if they remain unpatched."
}