Category Icon
Category Icon has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 4 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 6.5 out of 10. 2025 was the busiest year with 3 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (50%). Other recurring categories include Improper Restriction Of XML External Entity Reference, Path Traversal.
Every one of the 4 issues recorded for Category Icon has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, one record each. Category Icon is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-31825Category Icon <= 1.0.1 - Authenticated (Author+) Arbitrary File Download
Read the full analysisVulnerability Records
Category Icon
Author
pixelgrade
A WordPress plugin to easily attach an icon to a category, tag or any other taxonomy term. ** Now supports a category, tag or any other taxonomy image field, also. Please note that this plugin will not automatically output the icon or the image on the frontend of our site. It is up to you to query and output in your theme using the provided getter functions: get_term_icon_id(), get_term_icon_url(), get_term_image_id(), get_term_image_url().
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C