Manager for IcoMoon

Manager for IcoMoon has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Unrestricted Upload Of File With Dangerous Type.

Every one of the 2 issues recorded for Manager for IcoMoon has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by deokhunKim. Manager for IcoMoon is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
8.1/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Manager for IcoMoon vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2023-29386

Manager for Icomoon <= 2.0 - Unauthenticated Arbitrary File Upload via 'upload'

Read the full analysis

Vulnerability Records

2 records
Manager for IcoMoon banner
Latestv3.0

Manager for IcoMoon

albedo0

Author

albedo0

5.0(5)
100/100
Last Updated
2026-05-18 (4mo ago)
Active Installs
400+
Downloads
11,066
Requires WP
4.7.4+
Requires PHP
0+
Tested up to
WP 7.0.4
Created
2019-08-23 (7y ago)

Manager for IcoMoon helps you use icon fonts generated with the IcoMoon app inside WordPress. You can import a custom IcoMoon ZIP package, browse the available icons in the admin, and insert icons in your content with shortcodes or direct HTML from the Gutenberg editor. Main features: Import IcoMoon font ZIP packages, including packages generated by the newer IcoMoon app. Analyze a custom font package before installing it. Preview new and removed icons before replacing the current font. Detect removed icons that may already be used in post content. Warn when IcoMoon settings such as class prefix or postfix change and may affect direct HTML icons. Optionally update existing direct HTML icon classes when compatible icons still exist. Insert icons from the Gutenberg editor as shortcode or HTML. Organize icons into categories by using a separator in IcoMoon icon names. List available icons with their shortcode, HTML markup, and code. Restore the default icon pack if needed. Shortcodes are generally safer for long-term content because they rely on the icon name. Direct HTML gives more markup control, but may be affected when generated CSS classes change. Quick start Create your icon font in the IcoMoon app. If you want categories, rename icons with a separator between the category and the icon name. Example: social--facebook with separator -- will be listed in category social. Download the font ZIP from IcoMoon. Upload the ZIP from the plugin upload screen and review the import summary before installation. Configure the same category separator in the plugin settings if you use categorized names. Insert icons with shortcodes or the Gutenberg editor buttons. Before replacing an existing font pack, keep a copy of your IcoMoon project or manifest file. Removed icons can stop displaying in existing content.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C