CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts <= 4.2 - Cross-Site Request Forgery to Settings Update
medium
The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation on the cits_settings_tab() function. This makes it possible for unauthenticated atta...
- CVSS:
- 4.3
- Affected:
- up to 4.2
- Fix:
- No patched version reported
- Disclosed:
- Mar 21, 2025
CVE-2025-0807 on NVD →
CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts <= 4.2 - Cross-Site Request Forgery to Font Assignment Deletion
medium
The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.2. This is due to missing or incorrect nonce validation on the cits_assign_fonts_tab() function. This makes it possible for unauthenticated...
- CVSS:
- 4.3
- Affected:
- up to 4.2
- Fix:
- No patched version reported
- Disclosed:
- Mar 21, 2025
CVE-2024-13768 on NVD →
CITS Support svg, webp Media and TTF,OTF File Upload <= 2.1.0 - Authenticated(Author+) Stored Cross-Site Scripting via SVG Upload
medium
The CITS Support svg, webp Media and TTF,OTF File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG upload in versions up to, and including, 2.1.0 due to insufficient SVG sanitization. This makes it possible for authenticated attackers with Author permissions or above to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 3.0
- Fixed in:
- 3.0
- Disclosed:
- Oct 9, 2023
CVE-2023-5458 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database