plugin

Category Icon Vulnerabilities

8 known security issues reported for the Category Icon WordPress plugin. Most recent disclosed Dec 25, 2025.

4 medium

Running Category Icon on your site? Check whether your installed version is affected.

Scan your site free

Category Icon <= 1.0.2 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and above, to inject arbitrary web scripts in pages that wi...

CVSS:
4.4
Affected:
up to 1.0.2
Fixed in:
1.0.3
Disclosed:
Dec 25, 2025

CVE-2025-68525 on NVD →

Category Icon [category-icon] <= 1.0.2 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Category Icon category-icon allows Stored XSS.This issue affects Category Icon: from n/a through <= 1.0.2.

Affected:
up to 1.0.2
Fix:
No patched version reported
Disclosed:
Dec 24, 2025

CVE-2025-68525 on NVD →

Category Icon [category-icon] <= 1.0.2 (unfixed + closed)

unknown

[en] Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon allows XML Entity Linking. This issue affects Category Icon: from n/a through 1.0.2.

Affected:
up to 1.0.2
Fix:
No patched version reported
Disclosed:
Jun 9, 2025

CVE-2025-31039 on NVD →

Category Icon <= 1.0.1 - Authenticated (Author+) XML External Entity Injection

medium

The Category Icon plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and including, 1.0.1. This may make it possible for allow authenticated attackers, with author-level access and above, to extract sensitive data or achieve code execution in vulnerable configurations.

CVSS:
6.3
Affected:
up to 1.0.1
Fixed in:
1.0.2
Disclosed:
Jun 3, 2025

CVE-2025-31039 on NVD →

Category Icon <= 1.0.1 - Authenticated (Author+) Arbitrary File Download

medium

The Category Icon plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
6.5
Affected:
up to 1.0.1
Fixed in:
1.0.2
Disclosed:
Apr 3, 2025

CVE-2025-31825 on NVD →

Category Icon [category-icon] <= 1.0.0 (unfixed + closed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pixelgrade Category Icon allows Path Traversal. This issue affects Category Icon: from n/a through 1.0.0.

Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
Apr 3, 2025

CVE-2025-31825 on NVD →

Category Icon [category-icon] < 1.0.1 (closed)

unknown

[en] The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrar...

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Oct 12, 2024

CVE-2024-8915 on NVD →

Category Icon <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

medium

The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web...

CVSS:
6.4
Affected:
up to 1.0.0
Fixed in:
1.0.1
Disclosed:
Oct 11, 2024

CVE-2024-8915 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database