plugin

Olympus Google Fonts Vulnerabilities

6 known security issues reported for the Olympus Google Fonts WordPress plugin. Most recent disclosed Nov 1, 2024.

3 medium

Running Olympus Google Fonts on your site? Check whether your installed version is affected.

Scan your site free

Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts [olympus-google-fonts] < 3.7.8

unknown

[en] Missing Authorization vulnerability in Fonts Plugin Fonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fonts: from n/a through 3.7.7.

Affected:
up to 3.7.8
Fixed in:
3.7.8
Disclosed:
Nov 1, 2024

CVE-2024-43302 on NVD →

Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts [olympus-google-fonts] < 3.7.8

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.

Affected:
up to 3.7.8
Fixed in:
3.7.8
Disclosed:
Aug 26, 2024

CVE-2024-43301 on NVD →

Fonts <= 3.7.7 - Cross-Site Request Forgery

medium

The Fonts plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.7. This is due to missing or incorrect nonce validation on the manage_kits() function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged re...

CVSS:
6.1
Affected:
up to 3.7.7
Fixed in:
3.7.8
Disclosed:
Aug 16, 2024

CVE-2024-43301 on NVD →

Fonts <= 3.7.7 - Missing Authorization

medium

The Fonts plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the get_kits() and manage_kits() function in versions up to, and including, 3.7.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to access and u...

CVSS:
5.4
Affected:
up to 3.7.7
Fixed in:
3.7.8
Disclosed:
Aug 16, 2024

CVE-2024-43302 on NVD →

Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts [olympus-google-fonts] < 3.0.3

unknown

[en] The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Sep 20, 2021

CVE-2021-24637 on NVD →

Google Fonts Typography <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via blockType arguments

medium

The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitize some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

CVSS:
5.4
Affected:
up to 3.0.3
Fixed in:
3.0.3
Disclosed:
Aug 23, 2021

CVE-2021-24637 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database