plugin

Use Any Font Vulnerabilities

4 known security issues reported for the Use Any Font WordPress plugin. Most recent disclosed Sep 25, 2024.

4 medium

Running Use Any Font on your site? Check whether your installed version is affected.

Scan your site free

Use Any Font <= 6.3.08 - Cross-Site Request Forgery

medium

The Use Any Font plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.3.08. This is due to missing or incorrect nonce validation on the uaf_trigger_actions() function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request gran...

CVSS:
4.3
Affected:
up to 6.3.08
Fixed in:
6.3.09
Disclosed:
Sep 25, 2024

CVE-2024-47305 on NVD →

Use Any Font | Custom Font Uploader <= 6.2.7 - Cross-Site Scripting

medium

The Use Any Font | Custom Font Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters such as 'font_key' and 'elements' in versions up to, and including, 6.2.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inj...

CVSS:
6.4
Affected:
up to 6.2.7
Fixed in:
6.2.8
Disclosed:
May 10, 2022

Use Any Font <= 6.1.7 - Cross-Site Request Forgery to API Key Deactivation

medium

Cross-Site Request Forgery (CSRF) in Use Any Font (WordPress plugin) <= 6.1.7 allows an attacker to deactivate the API key.

CVSS:
5.4
Affected:
up to 6.1.7
Fixed in:
6.1.8
Disclosed:
Mar 30, 2022

CVE-2022-27851 on NVD →

Use Any Font <= 6.2.0 - Unauthenticated Arbitrary CSS Appending

medium

The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthenticated users to send arbitrary CSS which will then be processed by the frontend for all users. Due to the lack of sanitisation and escaping in the backend, it could also...

CVSS:
6.1
Affected:
up to 6.2.1
Fixed in:
6.2.1
Disclosed:
Jan 31, 2022

CVE-2021-24977 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database