Stored Cross-Site Scripting Vulnerability in WP-Iconics Plugin by WordPress
CVE-2025-12671
6.4MEDIUM
What is CVE-2025-12671?
The WP-Iconics plugin for WordPress is susceptible to stored cross-site scripting vulnerabilities due to inadequate input sanitization and output escaping. This flaw affects multiple parameters of the 'wp_iconics' shortcode, enabling authenticated attackers with Contributor-level access or higher to inject malicious scripts into pages. These injected scripts can execute whenever a user accesses the compromised page, posing significant risks to user security and data integrity.
Affected Version(s)
WP-Iconics * <= 0.0.4