The WPScan team reports that the WPIcons plugin is vulnerable to a remote code execution bug, available to site administrators: https://wpscan.com/vulnerability/a30212a0-c910-4657-aee1-4a2d72c77983. No patch is available from WordPress, so users of WPIcons remain vulnerable.