750
VMScore

CVE-2025-26937

CVSSv4: NA | CVSSv3: 6.5 | CVSSv2: NA | VMScore: 750 | EPSS: 0.0004 | KEV: Not Included
Published: 25/02/2025 Updated: 25/02/2025

Vulnerability Summary

Stored Cross-Site Scripting Vulnerability in bPlugins Icon List Block <= 1.1.3

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block allows Stored XSS. This issue affects Icon List Block: from n/a up to and including 1.1.3.

Solution

Update the WordPress Icon List Block wordpress plugin to the latest available version (at least 1.1.4).
Vulnerable Product Search on Vulmon Subscribe to Product

bplugins icon list block