CVE · Medium

CVE-2023-29387 — Manager for IcoMoon [manager-for-icomoon] < 2.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-29387 Manager for IcoMoon [manager-for-icomoon] < 2.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.2 2.2 2023-05-04

CVE-2023-29387

The Manager for IcoMoon WordPress plugin before version 2.2 contains a cross-site scripting vulnerability that was discovered by deokhunKim and reported to the WordPress plugin review team on April 5, 2023. An attacker could exploit this flaw to inject malicious scripts into a website, enabling them to execute redirects, display advertisements, or deploy other HTML-based attacks when visitors access the site. No patched version has been made available to address this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.