plugin

Menu Icons Vulnerabilities

4 known security issues reported for the Menu Icons WordPress plugin. Most recent disclosed Feb 3, 2026.

3 medium

Running Menu Icons on your site? Check whether your installed version is affected.

Scan your site free

Menu Icons by ThemeIsle <= 0.13.20 - Authenticated (Author+) Stored Cross-Site Scripting

medium

The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_wp_attachment_image_alt’ post meta in all versions up to, and including, 0.13.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level acces...

CVSS:
6.4
Affected:
up to 0.13.20
Fixed in:
0.13.21
Disclosed:
Feb 3, 2026

CVE-2026-1755 on NVD →

Menu Icons by ThemeIsle [menu-icons] < 0.13.14

unknown

[en] The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and...

Affected:
up to 0.13.14
Fixed in:
0.13.14
Disclosed:
May 16, 2024

CVE-2024-4635 on NVD →

Menu Icons by ThemeIsle <= 0.13.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload

medium

The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above...

CVSS:
6.4
Affected:
up to 0.13.13
Fixed in:
0.13.14
Disclosed:
May 15, 2024

CVE-2024-4635 on NVD →

ThemeIsle SDK <= Various Versions - Missing Authorization

medium

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track...

CVSS:
5.3
Affected:
up to 0.13.8
Fixed in:
0.13.9
Disclosed:
Feb 1, 2024

CVE-2024-1047 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database