CVE-2022-0471
The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue
Date published : 2022-04-11
https://plugins.trac.wordpress.org/changeset/2695862
https://wpscan.com/vulnerability/499bfee4-b481-4276-b6ad-0eead6680f66
