CVE-2026-2496Disclosure

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_awesome` shortcode in all versions up to, and including, 2.0. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-21); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Patch / Workaround · 2026-03-22: 1Technical Details · 2026-03-21: 1Technical Details · 2026-03-22: 103-2103-22
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-211
Disclosure1
2026-03-221
Patch1
Full discourse2 posts
  • Fernando Karl@fernandokarl
    Patch

    ⚠️ WordPress users: The Ed's Font Awesome plugin (<=2.0) is vulnerable to Stored XSS! 🎯 Immediate actions: update or remove, disable shortcodes, and review user permissions. Ensure your site is secure! 🛡️ 👉 Learn more: https://www.tenable.com/cve/CVE-2026-2496 #Cybersecurity #WordPress #XSS

    Post summary

    The post announces a stored XSS flaw in Ed's Font Awesome plugin (<=2.0) and urges WordPress users to patch, remove, disable shortcodes, and review permissions.

    0000033
    259 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2496 The Ed's Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `eds_font_awesome` shortcode in all versions up to, and includi… https://www.cve.org/CVERecord?id=CVE-2026-2496

    Post summary

    CVE-2026-2496 is a stored cross‑site scripting vulnerability in Ed’s Font Awesome WordPress plugin that affects all versions up to the specified point.

    0000074
    56.8K followersView on X

Explore more