cvemon logocvemon logo

Activity

Trending

CVEs

CVE-2025-26937

Published Feb 25, 2025

Last updated 2 days ago

  1. Overview

  2. Weaknesses

  3. Social media

  4. References

Overview

Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block icon-list-block allows Stored XSS.This issue affects Icon List Block: from n/a through <= 1.1.3.
Source
audit@patchstack.com
NVD status
Deferred

Weaknesses

audit@patchstack.com
CWE-79

Social media

Hype score
Not currently trending
  1. CVE-2025-26937 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block allows Stored XSS. This issue affects Icon List Block https://t.co/0faOIRKnV7

    @VulmonFeeds

    25 Feb 2025

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-26937 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Icon List Block allows Stored XSS. This issue affects I… https://t.co/zqkbinRFsB

    @CVEnew

    25 Feb 2025

    144 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.

  • https://nvd.nist.gov/vuln/detail/CVE-2025-26937
  • https://patchstack.com/database/Wordpress/Plugin/icon-list-block/vulnerability/wordpress-icon-list-block-plugin-1-1-3-cross-site-scripting-xss-vulnerability?_s_id=cve
TRY INTRUDER
Intruder logo

© 2026 Intruder Systems Ltd.

AboutPrivacySitemapFeeds