plugin

Ts Webfonts For Sakura Vulnerabilities

6 known security issues reported for the Ts Webfonts For Sakura WordPress plugin. Most recent disclosed Nov 9, 2023.

3 medium

Running Ts Webfonts For Sakura on your site? Check whether your installed version is affected.

Scan your site free

TS Webfonts for さくらのレンタルサーバ [ts-webfonts-for-sakura] < 3.1.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in SAKURA Internet Inc. TS Webfonts for さくらのレンタルサーバ plugin <= 3.1.2 versions.

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Nov 9, 2023

CVE-2023-34169 on NVD →

TS Webfonts for さくらのレンタルサーバ [ts-webfonts-for-sakura] < 3.1.3

unknown

[en] Cross-site request forgery (CSRF) vulnerability in TS Webfonts for SAKURA 3.1.2 and earlier allows a remote unauthenticated attacker to hijack the authentication of a user and to change settings by having a user view a malicious page.

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Jul 21, 2023

CVE-2023-32625 on NVD →

TS Webfonts for さくらのレンタルサーバ [ts-webfonts-for-sakura] < 3.1.3

unknown

[en] Cross-site scripting vulnerability in TS Webfonts for SAKURA 3.1.0 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

Affected:
up to 3.1.3
Fixed in:
3.1.3
Disclosed:
Jul 21, 2023

CVE-2023-32624 on NVD →

TS Webfonts for SAKURA <= 3.1.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The TS Webfonts for SAKURA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to injec...

CVSS:
4.4
Affected:
up to 3.1.0
Fixed in:
3.1.1
Disclosed:
Jul 20, 2023

CVE-2023-32624 on NVD →

TS Webfonts for SAKURA <= 3.1.2 - Cross-Site Request Forgery

medium

The TS Webfonts for SAKURA plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.2. This is due to missing or incorrect nonce validation on the '2' and '3' actions of typesquare_admin_init() function. This makes it possible for unauthenticated attackers to update fontpro...

CVSS:
4.3
Affected:
up to 3.1.2
Fixed in:
3.1.3
Disclosed:
Jul 20, 2023

CVE-2023-32625 on NVD →

TS Webfonts for さくらのレンタルサーバ <= 3.1.1 - Cross-Site Request Forgery

medium

The TS Webfonts for さくらのレンタルサーバ plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.1.1. This is due to missing or incorrect nonce validation on the typesquare_admin_init function. This makes it possible for unauthenticated attackers to invoke this function an...

CVSS:
4.3
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
May 31, 2023

CVE-2023-34169 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database