Input validation vulnerability in Category Icon 1.0.2

The Category Icon plugin for WordPress has a security issue called XML External Entity Injection (XXE) in versions 1.0.2 and below. This means that attackers who are logged in and have author or higher access can access private information or run their own code on websites that use this plugin.

Detected in:

Category Icon open vulnerable versions: >= * <= 1.0.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.