Cross-Site Request Forgery Vulnerability in EdesaC Extra Options - Favicons
CVE-2025-23508
7.1HIGH
What is CVE-2025-23508?
A Cross-Site Request Forgery (CSRF) vulnerability in the EdesaC Extra Options โ Favicons plugin allows attackers to exploit the pluginโs functionality to execute stored XSS attacks. This vulnerability allows unauthorized actions to be performed without the user's consent, potentially compromising sensitive information and enabling further attacks on the website. Affected versions range from n/a up to 1.1.0, making it essential for users to update their plugins to the latest version to mitigate risks.
Affected Version(s)
Extra Options โ Favicons 0 <= 1.1.0