Extension WordPress
Vulnérabilités Category Icon
Cette page rassemble les failles publiées pour Category Icon, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Category Icon
4 fiches
Category Icon <= 1.0.2 – Authenticated (Editor+) Stored Cross-Site Scripting
The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level access and…
*-1.0.2
1.0.3
25/12/2025
Category Icon <= 1.0.1 – Authenticated (Author+) XML External Entity Injection
The Category Icon plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in versions up to, and including, 1.0.1. This may make it possible for allow authenticated attackers, with author-level access and above, to extract sensitive…
*-1.0.1
1.0.2
03/06/2025
Category Icon <= 1.0.1 – Authenticated (Author+) Arbitrary File Download
The Category Icon plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of arbitrary files…
*-1.0.1
1.0.2
03/04/2025
Category Icon <= 1.0.0 – Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload
The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-1.0.0
1.0.1
11/10/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.