Menu Icons by ThemeIsle <= 0.13.20 - Authenticated (Author+) Stored Cross-Site Scripting
medium
The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_wp_attachment_image_alt’ post meta in all versions up to, and including, 0.13.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level acces...
- CVSS:
- 6.4
- Affected:
- up to 0.13.20
- Fixed in:
- 0.13.21
- Disclosed:
- Feb 3, 2026
CVE-2026-1755 on NVD →
Menu Icons by ThemeIsle [menu-icons] < 0.13.14
unknown
[en] The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and...
- Affected:
- up to 0.13.14
- Fixed in:
- 0.13.14
- Disclosed:
- May 16, 2024
CVE-2024-4635 on NVD →
Menu Icons by ThemeIsle <= 0.13.13 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload
medium
The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ function in versions up to, and including, 0.13.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level permissions and above...
- CVSS:
- 6.4
- Affected:
- up to 0.13.13
- Fixed in:
- 0.13.14
- Disclosed:
- May 15, 2024
CVE-2024-4635 on NVD →
ThemeIsle SDK <= Various Versions - Missing Authorization
medium
Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the register_reference() function in various versions. This makes it possible for unauthenticated attackers to update options values that allow ThemeIsle to track...
- CVSS:
- 5.3
- Affected:
- up to 0.13.8
- Fixed in:
- 0.13.9
- Disclosed:
- Feb 1, 2024
CVE-2024-1047 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database