Executive brief
Favicon Rotator, a WordPress plugin used to manage and rotate site icons, contains a security vulnerability that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This issue affects all versions up to 1.2.11 and can be exploited without needing a password.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Favicon Rotator plugin for WordPress (versions <= 1.2.11) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary JavaScript or HTML payloads. Exploitation requires a victim (typically a privileged user) to perform an action, such as clicking a malicious link or visiting a crafted page (User Interaction: Required). Successful exploitation can lead to session hijacking, unauthorized actions in the context of the user's browser, or site defacement. The issue is resolved in version 1.2.12.
Affected products
- Favicon Rotator Favicon Rotator <= 1.2.11
Timeline
- 2026-03-04: other: Reported by researcher timomangcut
- 2026-04-29: advisory: Initial advisory published by Patchstack
- 2026-06-15: disclosed: NVD publication date
- 2026-04-29: patched: Version 1.2.12 released to address the vulnerability