CVE-2025-12671: WP-Iconics <= 0.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wpiconics' shortcode in all versions up to, and including, 0.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12671?
CVE-2025-12671 has a severity rating classified as high due to the potential impact of Stored Cross-Site Scripting.
How do I fix CVE-2025-12671?
To fix CVE-2025-12671, update the WP-Iconics plugin to version 0.0.5 or later which includes fixes for the vulnerability.
Who is affected by CVE-2025-12671?
CVE-2025-12671 affects users of the WP-Iconics plugin for WordPress in versions up to and including 0.0.4.
What type of vulnerability is CVE-2025-12671?
CVE-2025-12671 is categorized as a Stored Cross-Site Scripting vulnerability enabling the injection of malicious scripts.
Can CVE-2025-12671 be exploited remotely?
Yes, CVE-2025-12671 can be exploited remotely by authenticated attackers who can manipulate the shortcode parameters.