Favicon Rotator
Favicon Rotator has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Favicon Rotator has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Favicon Rotator is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-42649Favicon Rotator <= 1.2.11 - Unauthenticated Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Favicon Rotator
Author
Archetyped
Favicon Rotator makes it easy to customize the favicon for your site. Just add a favicon via the administration page and it will be displayed whenever someone visits your site. Highlights New: Set icon for Touch devices (Android, iPhone, iPad, iPod Touch, etc.) Simply point and click to add a favicon to your site Supports adding multiple icons, from which a randomly selected favicon will be displayed. Automatic icon conversion for large images (smaller files and faster loading) Usage Go to Theme > Favicon admin page to add/upload image(s) to use for the favicon That’s it! The favicon will be displayed in visitors’ browsers when they visit your site Notes Verify that your theme uses the wp_head() template tag If you add multiple icons, then a randomly selected icon will be displayed each time the site is loaded More Information on Favicon Rotator’s Official Page
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C