Font Awesome 4.0.0-rc15 and 4.0.0-rc16 - API Token Exposure

2020-03-11 00:00
Anonymous

Strategic Overview

Status
Patched in 4.0.0-rc17
Affected PluginFont Awesome
Affected Version4.0.0-rc15 – 4.0.0-rc15 · 2 branches
CVSS6.5Medium
CVEN/A
View all Font Awesome vulnerabilities

Vulnerability Overview

The Font Awesome plugin for WordPress versions 4.0.0-rc15 and 4.0.0-rc16 are vulnerable to API Token Exposure. The vulnerability exposes the Font Awesome API token and access token for users who have configured the plugin to use a kit. If compromised, these tokens could give an unauthorized person access to that user’s list of kits and kit settings.

Technical Analysis

REMEDIATION: Update to version 4.0.0-rc17, or a newer patched version --- IDENTIFIER: CWE-202 (Exposure of Sensitive Information Through Data Queries) When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C