plugin

Host Google Fonts Pro Vulnerabilities

2 known security issues reported for the Host Google Fonts Pro WordPress plugin. Most recent disclosed Aug 13, 2026.

1 critical 1 high

Running Host Google Fonts Pro on your site? Check whether your installed version is affected.

Scan your site free

OMGF Pro <= 5.2.7 - Unauthenticated Arbitrary File Download

high

The OMGF Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.2.7. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
7.5
Affected:
up to 5.2.7
Fixed in:
5.2.8
Disclosed:
Aug 13, 2026

CVE-2026-61980 on NVD →

OMGF Pro <= 5.2.6 - Unauthenticated Arbitrary File Upload via @import URL Reflection

critical

The OMGF Pro plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 5.2.6. This is due to the ExternalStylesheets::optimize() method extracting attacker-controlled @import URLs from the rendered HTML, fetching their contents via wp_remote_get(), and writing those conte...

CVSS:
9.8
Affected:
up to 5.2.6
Fixed in:
5.2.7
Disclosed:
Jun 25, 2026

CVE-2026-57700 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database