plugin

Categories Images Vulnerabilities

2 known security issues reported for the Categories Images WordPress plugin. Most recent disclosed Apr 17, 2026.

2 medium

Running Categories Images on your site? Check whether your installed version is affected.

Scan your site free

Categories Images <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'z_taxonomy_image' Shortcode

medium

The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.1, via the 'z_taxonomy_image' shortcode. This is due to the shortcode rendering path passing attacker-controlled class input into a fallback image builder that concatenates HTML attributes witho...

CVSS:
5.4
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Apr 17, 2026

CVE-2026-2505 on NVD →

Categories Images <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in page...

CVSS:
6.4
Affected:
up to 3.3.1
Fixed in:
3.3.2
Disclosed:
Mar 14, 2026

CVE-2026-40734 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database