First published: Tue Feb 25 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block allows Stored XSS. This issue affects Icon List Block: from n/a through 1.1.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Icon List Block | <=1.1.3 | |
WordPress Icon List Block | <=1.1.3 |
Update the WordPress Icon List Block wordpress plugin to the latest available version (at least 1.1.4).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26937 is classified as a high severity vulnerability due to the potential for stored cross-site scripting (XSS).
To fix CVE-2025-26937, update the bPlugins Icon List Block plugin to version 1.1.4 or later.
CVE-2025-26937 affects the bPlugins Icon List Block plugin versions up to and including 1.1.3.
CVE-2025-26937 is an improper neutralization vulnerability that leads to stored cross-site scripting (XSS) in web pages.
Yes, if exploited, CVE-2025-26937 can allow an attacker to execute scripts in the context of a user's session, potentially leading to data theft.