Junglewise Threat Intelligence

CVE-2026-42754: phbernard Favicon by RealFaviconGenerator Reflected XSS

CVE-2026-42754 · Severity: high · CVSS 7.1 · Published 2026-05-27

Executive brief

The Favicon by RealFaviconGenerator plugin for WordPress, which helps website owners manage site icons, contains a security vulnerability that allows for reflected cross-site scripting (XSS). An attacker could trick a site administrator or visitor into clicking a malicious link, allowing the attacker to run unauthorized code in their browser. This could lead to the theft of login sessions, unauthorized actions on the website, or the redirection of users to malicious sites.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the phbernard Favicon (favicon-by-realfavicongenerator) plugin for WordPress. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by crafting a malicious URL and persuading a user to visit it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. The issue affects all versions up to and including 1.3.46.

Affected products

  • phbernard Favicon by RealFaviconGenerator n/a through 1.3.46

Timeline

  • 2026-05-27: advisory: NVD and Patchstack published the vulnerability details.

References