CVE-2021-24935
06.12.2021, 16:15
The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues
Vendor | Product | Version |
---|---|---|
wp_google_fonts_project | wp_google_fonts | 𝑥 < 3.1.5 |
𝑥
= Vulnerable software versions