CVE-2025-49395: WordPress Themify Icons Plugin <= 2.0.3 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Icons allows Stored XSS. This issue affects Themify Icons: from n/a through 2.0.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify Icons themify-icons allows Stored XSS.This issue affects Themify Icons: from n/a through <= 2.0.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49395?
CVE-2025-49395 is classified as a Stored Cross-site Scripting (XSS) vulnerability affecting Themify Icons.
How do I fix CVE-2025-49395?
To fix CVE-2025-49395, update Themify Icons to version 2.0.4 or later.
What versions of Themify Icons are affected by CVE-2025-49395?
CVE-2025-49395 affects Themify Icons from version n/a through 2.0.3.
Can CVE-2025-49395 affect my website?
Yes, CVE-2025-49395 can affect websites using affected versions of Themify Icons, leading to potential XSS attacks.
What plugin does CVE-2025-49395 affect in WordPress?
CVE-2025-49395 affects the Themify Icons Plugin for WordPress up to version 2.0.3.