Allow HTML in Category Descriptions

Allow HTML in Category Descriptions has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Allow HTML in Category Descriptions has a vendor fix available, so running the current release closes it.

All of these findings were reported by ZAST.AI. Allow HTML in Category Descriptions is installed on roughly 8,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
4.4/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Allow HTML in Category Descriptions vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.4CVE-2026-0693

Allow HTML in Category Descriptions <= 1.2.4 - Authenticated (Administrator+) Stored Cross-Site Scripting via Category Descriptions

Read the full analysis

Vulnerability Records

1 records
Allow HTML in Category Descriptions banner
Latestv1.2.5

Allow HTML in Category Descriptions

Arno Esterhuizen

Author

Arno Esterhuizen

5.0(41)
100/100
Last Updated
2026-03-05 (6mo ago)
Active Installs
8,000+
Downloads
130,515
Requires WP
2.5+
Requires PHP
7.0+
Tested up to
WP 6.9.7
Created
2008-06-11 (19y ago)

When you add text to the category description textarea and save the category, WordPress runs content filters that strips out all but the most basic formatting tags. This plugin disables those filters for roles with the necessary permissions. Any html code you add to the category description will not be stripped out. This plugin does not do anything other than disable the filters. It does not protect you from entering invalid HTML, nor does it help you create WYSIWYG HTML. You can use the post or page composing screen to help you create the text and formatting. Switch to the &#8216;code’ tab and copy the HTML code into the category description field.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C