Font Awesome 4.0.0-rc15 and 4.0.0-rc16 - API Token Exposure
2020-03-11 00:00
AnonymousStrategic Overview
StatusPatched in 4.0.0-rc17
Affected PluginFont Awesome
Affected Version
4.0.0-rc15 – 4.0.0-rc15 · 2 branchesCVSS6.5Medium
CVE
N/AVulnerability Overview
The Font Awesome plugin for WordPress versions 4.0.0-rc15 and 4.0.0-rc16 are vulnerable to API Token Exposure. The vulnerability exposes the Font Awesome API token and access token for users who have configured the plugin to use a kit. If compromised, these tokens could give an unauthorized person access to that user’s list of kits and kit settings.
Technical Analysis
REMEDIATION: Update to version 4.0.0-rc17, or a newer patched version --- IDENTIFIER: CWE-202 (Exposure of Sensitive Information Through Data Queries) When trying to keep information confidential, an attacker can often infer some of the information by using statistics.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C