Ed's Font Awesome

Ed's Font Awesome has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Ed's Font Awesome has a vendor fix available, so running the current release closes it.

All of these findings were reported by zakaria. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
6.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Ed's Font Awesome vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2026-2496

Ed's Font Awesome <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

Read the full analysis

Vulnerability Records

1 records
Ed's Font Awesome banner
Latestv3.0.1

Ed's Font Awesome

waianaeboy702

Author

waianaeboy702

0.0(0)
0/100
Last Updated
2026-05-09 (4mo ago)
Active Installs
0+
Downloads
1,515
Requires WP
6.8+
Requires PHP
7.0+
Tested up to
WP 6.9.7
Created
2021-03-06 (6y ago)

The ultimate Font Awesome plugin for WordPress. Use all of the free font awesome icons in one place. Features: Basic icon shortcode with style, name, size, and color Mask icons — combine any two icons Mask circle icons — place any icon inside a circle Rotate and flip icons NEW: Animated icons — spin, pulse, beat, fade, bounce, flip, shake NEW: Layered/stacked icons — stack icons, text, and counters NEW: Icon links — wrap any icon in a clickable link NEW: Color attribute — set icon color on any shortcode Font Awesome 6.7.2 included 1.0.2 Added option for size to require only size attribute without fa- prefix. 1.0.3 Removed unecessary font-awesome files for thinner plugin size. 1.0.4 Added Spin feature and mask feature. 1.0.5 Updated Instructions 2.0 Updated Font Awesome to vs. 6.7.2. This version Adds X social media icon 2.1 Security fix: Sanitized and escaped all shortcode attribute outputs to prevent Stored XSS (CVE-2026-2496) Applied esc_attr() to all shortcode HTML attribute outputs Applied esc_html() to admin notice helper function Tested up to WordPress 6.8 3.0.1 Security: Confirmed all shortcode attributes properly escaped with esc_attr(), esc_html(), esc_url() Version bump to clearly differentiate from vulnerable v2.0 (CVE-2026-2496) 3.0 NEW: Animated icons shortcode [eds_fa_spin] — spin, pulse, beat, fade, bounce, flip, shake NEW: Layered/stacked icons [eds_fa_layers] with [eds_fa_layer_icon], [eds_fa_layer_text], [eds_fa_layer_counter] NEW: Icon link shortcode [eds_fa_link] — wrap any icon in a clickable link NEW: Color attribute added to all icon shortcodes Improved: Admin scripts only load on plugin pages (no longer on every admin page) Improved: Cleaner code structure with constants and security best practices Updated dashboard with full shortcode reference and live previews

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C