Description
WordPress Plugin Effectively Add & Customize Free Icons For WordPress Menus-WP Menu Icons Lite [only if downloaded via the vendor website] contains suspicious code. Attackers can exploit this issue to perform a variety of actions. Successful attacks will compromise the affected application and possibly the webserver or computer. WordPress Plugin Effectively Add & Customize Free Icons For WordPress Menus-WP Menu Icons Lite version 1.0.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.9 or latest
References
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2016-2221)
WordPress Plugin DX Share Selection Cross-Site Request Forgery (1.4)
WordPress Plugin WP-OliveCart Multiple Vulnerabilities (3.1.2)
WebLogic Improper Privilege Management Vulnerability (CVE-2026-35291)
WordPress Plugin SP Project & Document Manager Unspecified Vulnerability (2.6.2.5)