CVE-2024-7864
Severity CVSS v4.0: 
            Pending analysis
                                                    Type: 
          
                          CWE-352
                        Cross-Site Request Forgery (CSRF)
          
        Publication date: 
                          13/09/2024
                  Last modified: 
                          27/09/2024
                  Description
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete arbitrary files on the server
              Impact
Base Score 3.x
          6.50
        Severity 3.x
          MEDIUM
        Vulnerable products and versions
| CPE | From | Up to | 
|---|---|---|
| cpe:2.3:a:pixeljar:favicon_generator:*:*:*:*:*:wordpress:*:* | 2.1 (excluding) | 
To consult the complete list of CPE names with products and versions, see this page



