CVE-2026-42649: WordPress Favicon Rotator plugin <= 1.2.11 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions.
Metrics
- CVSS v3.1
- 7.1
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A reflected or stored cross-site scripting (XSS) vulnerability affects the Favicon Rotator WordPress plugin at version 1.2.11 and earlier. The flaw is reachable over the network without any authentication, but requires a victim to interact with a malicious link or page. Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the victim's browser, enabling session hijacking, page content manipulation, or redirection to attacker-controlled destinations. HarborGuard tracks this advisory and will make a patched-image rebuild available the moment an upstream fix is published.
HarborGuard Coverage
Detection of CVE-2026-42649 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images, including custom-built WordPress images that bundle the Favicon Rotator plugin. Any image carrying an affected version of the plugin is flagged automatically.
AvailableHarborGuard surfaces this CVE with its CVSS 3.1 score of 7.1 (HIGH) and applies per-environment compliance policy weighting to prioritize it appropriately within each customer org. Triage routing is available to direct findings to the right team inbox based on the policies each customer has configured.
AvailableNo upstream fix version has been published for CVE-2026-42649 yet. HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment the Favicon Rotator maintainer ships a corrected release.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The vulnerable plugin endpoint is exposed over the network, so an attacker must be able to reach the WordPress installation via HTTP or HTTPS.
- AuthenticationNot required
No account or session is needed; the attacker can send malicious input as an unauthenticated user.
- Victim interactionRequired
A victim must follow a crafted link or visit a page that delivers the malicious payload, making a social-engineering step necessary.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special race conditions or environmental preconditions to execute.
Blast Radius
- Attacker executes arbitrary JavaScript in the victim's browser session, allowing theft of session cookies or authentication tokens.
- Attacker modifies the visible content of the WordPress page as rendered in the victim's browser, enabling phishing or defacement from the victim's perspective.
- Attacker redirects the victim to an external, attacker-controlled site without further interaction.
- With the scope change (S:C) noted in the CVSS vector, injected script can affect browser contexts beyond the originating page, such as iframes or same-site resources.
How HarborGuard Handles This
Available on HarborGuard: detection of this CVE is active for any customer image that bundles the Favicon Rotator plugin at version 1.2.11 or earlier, including custom WordPress images built internally. Because no upstream fix has been published as of the CVE publication date (2026-06-15), HarborGuard monitors the advisory on every ingest cycle and will make a patched-image rebuild available automatically once a fixed version is released by Archetyped. In the interim, customers can apply compensating controls through HarborGuard network policies: isolating affected WordPress containers from untrusted external traffic, enabling egress filtering to restrict outbound connections from compromised sessions, or using a web application firewall rule to sanitize the relevant input parameter. For customers with auto-remediation enabled, a rebuilt image and regression test run will be triggered and a PR opened against affected workloads as soon as a fix version becomes available upstream.
- Archetyped / Favicon Rotator≤ 1.2.11
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L