Description
WordPress Plugin Font Awesome is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Font Awesome versions 4.0.0-rc15 and 4.0.0-rc16 are vulnerable.
Remediation
Update to plugin version 4.0.0-rc17 or latest
References
https://blog.fontawesome.com/font-awesome-wordpress-plugin-api-token-vulnerability-fixed/
https://plugins.svn.wordpress.org/font-awesome/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WP to Twitter Cross-Site Request Forgery (3.2.9)
WordPress Server-Side Request Forgery (SSRF) Vulnerability (CVE-2016-4029)
WordPress Plugin FireDrum Email Marketing PHP Object Injection (1.47)
AngularJS Inefficient Regular Expression Complexity Vulnerability (CVE-2024-21490)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1000399)