The Genie WP Favicon WordPress plugin through 0.5.2 does not have CSRF in place when updating the favicon, which could allow attackers to make a logged in admin change it via a CSRF attack
https://wpscan.com/vulnerability/26965878-c4c9-4f43-9e9a-6e58d6b46ef2