First published: Wed Sep 21 2022(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in SedLex FavIcon Switcher plugin <= 1.2.11 at WordPress allows plugin settings change.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sedlex Favicon-switcher | <=1.2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40219 has a medium severity level, indicating potential risk to affected users.
To fix CVE-2022-40219, update the SedLex Favicon Switcher plugin to version 1.2.12 or later.
CVE-2022-40219 allows an attacker to change plugin settings without user consent through CSRF.
CVE-2022-40219 affects SedLex Favicon Switcher plugin versions up to and including 1.2.11.
Users of the SedLex Favicon Switcher plugin in WordPress environments are affected by CVE-2022-40219.