Medium 5.9
2025-12-25< 1.0.3
Category Icon <= 1.0.2 - Authenticated (Editor+) Stored Cross-Site Scripting
Minimum safe version
1.0.3
Update to 1.0.3 or later to address 3 fixable vulnerabilities
Category Icon <= 1.0.2 - Authenticated (Editor+) Stored Cross-Site Scripting
WordPress Category Icon plugin <= 1.0.3 - XML External Entity (XXE) vulnerability
CVE-2025-31825
WordPress Category Icon Plugin <= 1.0.0 is vulnerable to Cross Site Scripting (XSS)