WP Google Fonts [wp-google-fonts] < 3.1.5 (closed)
unknown
[en] The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
- Disclosed:
- Dec 6, 2021
CVE-2021-24935 on NVD →
WP Google Fonts <= 3.1.4 - Reflected Cross-Site Scripting
medium
The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues
- CVSS:
- 6.1
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.5
- Disclosed:
- Nov 3, 2021
CVE-2021-24935 on NVD →
WP Google Fonts <= 3.1.3 - Reflected Cross-Site Scripting
medium
The WP Google Fonts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ googlefont_ajax_name’ parameter in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- CVSS:
- 6.1
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Aug 19, 2015
WP Google Fonts [wp-google-fonts] < 3.1.4 (closed)
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Vulnerable parameter is "googlefont_ajax_name".
Update the plugin.
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Aug 19, 2015
WP Google Fonts [wp-google-fonts] < 3.1.4 (closed)
unknown
The WP Google Fonts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ googlefont_ajax_name’ parameter in versions up to, and including, 3.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
- Disclosed:
- Aug 19, 2015
WP Google Fonts [wp-google-fonts] < 3.1.4 (closed)
unknown
The WP Google Fonts WordPress plugin was affected by an Authenticated Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database