Search Results (4 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-95595 1 Fontsplugin 1 Disable And Remove Google Fonts Gdpr Dsgvo Friendly 2026-10-07 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS. This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2.
CVE-2024-43301 1 Fontsplugin 1 Fonts 2025-01-23 7.1 High
Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.
CVE-2021-24637 1 Fontsplugin 1 Fonts 2024-11-21 5.4 Medium
The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.
CVE-2024-43302 1 Fontsplugin 1 Fonts 2024-11-13 4.3 Medium
Missing Authorization vulnerability in Fonts Plugin Fonts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fonts: from n/a through 3.7.7.