Surbma | Font Awesome
Surbma | Font Awesome has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Surbma | Font Awesome has a vendor fix available, so running the current release closes it.
All of these findings were reported by SOPROBRO. Surbma | Font Awesome is installed on roughly 90 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2024-51798Surbma | Font Awesome <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Surbma | Font Awesome
Author
Surbma
With this plugin you can use the iconic font and CSS toolkit, the Font Awesome icons. It is loading the css and the font files from the MaxCDN network, which means super fast loading, wherever your visitors are on this planet. You get also a very useful shortcode to use icons on your site: [fa class=”fa-camera-retro”] As you can see, you only need to add the icon name, that’s it. Isn’t it awesome? If you use the <i class="fa fa-camera-retro"></i> code, the WordPress editor will remove it, because it is an empty code, which “should be removed”. So with this shortcode, you can use the Font Awesome icons wherever you want. Font Awesome official site and all the icons: Font Awesome website »
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C