Stored XSS Vulnerability in Quick Favicon by Robert Cummings
CVE-2025-53287

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 June 2025

What is CVE-2025-53287?

A vulnerability has been identified in the Quick Favicon plugin developed by Robert Cummings, which allows for stored cross-site scripting (XSS). This issue arises due to improper sanitization of user inputs during web page generation, potentially allowing attackers to execute malicious scripts within the context of an affected website. The vulnerability impacts all versions of Quick Favicon up to 0.22.8, posing a risk to users' web environments. Ensuring proper input validation and sanitization can help mitigate this security threat.

Affected Version(s)

Quick Favicon <= 0.22.8

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.
CVE-2025-53287 : Stored XSS Vulnerability in Quick Favicon by Robert Cummings