High 8.8 Unfixed
2026-02-20≤ 2.5.1
CVE-2026-22354
Minimum safe version
2.4.3
Update to 2.4.3 or later to address 7 fixable vulnerabilities
CVE-2026-22354
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2023-39158
WordPress Download Woocommerce Category Banner Management Plugin <= 2.4.0 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Download Woocommerce Category Banner Management plugin <= 2.2.2 - Sensitive Information Disclosure vulnerability
WordPress Download Woocommerce Category Banner Management plugin <= 2.2.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
WordPress WooCommerce Category Banner Management plugin <= 1.1.0 - Unauthenticated Settings Change Vulnerability