“Experts at the Sucuri firm have discovered that any WordPress Plugin or theme that leverages the genericons package is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability due to an insecure file included with genericons.”
Source: Million wordpress websites vulnerable to DOM-based XSSSecurity Affairs