Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts [olympus-google-fonts] < 3.7.8
unknown
[en] Missing Authorization vulnerability in Fonts Plugin Fonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fonts: from n/a through 3.7.7.
- Affected:
- up to 3.7.8
- Fixed in:
- 3.7.8
- Disclosed:
- Nov 1, 2024
CVE-2024-43302 on NVD →
Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts [olympus-google-fonts] < 3.7.8
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.
- Affected:
- up to 3.7.8
- Fixed in:
- 3.7.8
- Disclosed:
- Aug 26, 2024
CVE-2024-43301 on NVD →
Fonts <= 3.7.7 - Cross-Site Request Forgery
medium
The Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.7. This is due to missing or incorrect nonce validation on the manage_kits() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged re...
- CVSS:
- 6.1
- Affected:
- up to 3.7.7
- Fixed in:
- 3.7.8
- Disclosed:
- Aug 16, 2024
CVE-2024-43301 on NVD →
Fonts <= 3.7.7 - Missing Authorization
medium
The Fonts plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the get_kits() and manage_kits() function in versions up to, and including, 3.7.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and u...
- CVSS:
- 5.4
- Affected:
- up to 3.7.7
- Fixed in:
- 3.7.8
- Disclosed:
- Aug 16, 2024
CVE-2024-43302 on NVD →
Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts [olympus-google-fonts] < 3.0.3
unknown
[en] The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Sep 20, 2021
CVE-2021-24637 on NVD →
Google Fonts Typography <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via blockType arguments
medium
The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitize some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.
- CVSS:
- 5.4
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.3
- Disclosed:
- Aug 23, 2021
CVE-2021-24637 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database