Allow HTML in Category Descriptions
Allow HTML in Category Descriptions has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Allow HTML in Category Descriptions has a vendor fix available, so running the current release closes it.
All of these findings were reported by ZAST.AI. Allow HTML in Category Descriptions is installed on roughly 8,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-0693Allow HTML in Category Descriptions <= 1.2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via Category Descriptions
Read the full analysisVulnerability Records

Allow HTML in Category Descriptions
Author
Arno Esterhuizen
When you add text to the category description textarea and save the category, WordPress runs content filters that strips out all but the most basic formatting tags. This plugin disables those filters for roles with the necessary permissions. Any html code you add to the category description will not be stripped out. This plugin does not do anything other than disable the filters. It does not protect you from entering invalid HTML, nor does it help you create WYSIWYG HTML. You can use the post or page composing screen to help you create the text and formatting. Switch to the ‘code’ tab and copy the HTML code into the category description field.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C