Description
WordPress Plugin Font Awesome is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Font Awesome versions 4.0.0-rc15 and 4.0.0-rc16 are vulnerable.
Remediation
Update to plugin version 4.0.0-rc17 or latest
References
https://blog.fontawesome.com/font-awesome-wordpress-plugin-api-token-vulnerability-fixed/
https://plugins.svn.wordpress.org/font-awesome/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Media Tags Cross-Site Scripting (3.2.0.2)
Joomla Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2018-11325)
WordPress Plugin WP People 'wp-people-popup.php' SQL Injection (2.0)
WordPress Plugin Floating Cart for WooCommerce Security Bypass (1.2.2)
WordPress Plugin Social Like Box and Page by WpDevArt Cross-Site Scripting (0.8.40)