PLUGIN SECURITY

Is Allow Html In Category Descriptions safe?

This plugin allows you to use unfiltered HTML in your category descriptions by disabling selected WordPress filters.

What this plugin does

  • Slug: allow-html-in-category-descriptions
  • Author: Arno Esterhuizen
  • 8000+ active installs
  • 100/100 rating (41 reviews on wordpress.org)
  • 130015 all-time downloads
  • On WordPress.org since 2008-06-11

categoriescategory descriptionsfilterhtml

Maintenance status

  • Latest known version: 1.2.5
  • Last updated: 2026-03-05 11:15am GMT
  • Tested up to WordPress: 6.9.7
  • Requires PHP: 7.0+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

1 known CVE on file for Allow Html In Category Descriptions.

CVE Vulnerability Type Severity Affected Fixed in Published Status
Allow HTML in Category Descriptions [allow-html-in-category-descriptions] <= 1.2.4 (unfixed) Unknown < 1.2.4 1.2.4 0000-00-00 ✓ fixed in latest
CVE-2026-0693 Allow HTML in Category Descriptions < 1.2.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via Category Descriptions Unknown < 1.2.5 1.2.5 ✓ fixed in latest

How to fix it

Keep Allow Html In Category Descriptions updated — 1.2.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.