Description
WordPress Plugin Font Awesome is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Font Awesome versions 4.0.0-rc15 and 4.0.0-rc16 are vulnerable.
Remediation
Update to plugin version 4.0.0-rc17 or latest
References
https://blog.fontawesome.com/font-awesome-wordpress-plugin-api-token-vulnerability-fixed/
https://plugins.svn.wordpress.org/font-awesome/trunk/readme.txt
Related Vulnerabilities
Ruby on Rails Uncontrolled Resource Consumption Vulnerability (CVE-2020-8185)
MySQL CVE-2021-2006 Vulnerability (CVE-2021-2006)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2044)
Oracle JRE CVE-2013-1557 Vulnerability (CVE-2013-1557)
WordPress Plugin Download Zip Attachments Arbitrary File Download (1.0.0)