Description
WordPress Plugin Font Awesome is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Font Awesome versions 4.0.0-rc15 and 4.0.0-rc16 are vulnerable.
Remediation
Update to plugin version 4.0.0-rc17 or latest
References
https://blog.fontawesome.com/font-awesome-wordpress-plugin-api-token-vulnerability-fixed/
https://plugins.svn.wordpress.org/font-awesome/trunk/readme.txt
Related Vulnerabilities
MySQL CVE-2024-21243 Vulnerability (CVE-2024-21243)
WordPress Plugin TallyKit Cross-Site Scripting (5.4)
WordPress Plugin ShareYourCart Information Disclosure (1.6.1)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3464)
Oracle Application Server CVE-2008-0344 Vulnerability (CVE-2008-0344)