← WordPress Vulnerabilities
WordPress security by component

Custom Logo

Custom Logo is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Feb 26, 2026; the highest CVE/CNA score is 4.4.

Plugin slug: custom-logo

CVE-2026-2499: Custom Logo: Cross-site scripting

Custom Logo is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.

PublishedFeb 26, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 26, 2026 CVE-2026-2499
Custom Logo: Cross-site scripting
Custom Logo is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.4
NVDPending