fontsplugin records
3 published records for vendor fontsplugin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-43302No exploit | WordPress Fonts plugin <= 3.7.7 - Broken Access Control vulnerabilityfontsplugin · fonts · CWE-862 | High8.8 | — | 0.4% | Nov 1, 2024 |
21Monitor | CVE-2021-24637No exploit | Fonts Plugin < 3.0.3 - Contributor+ Stored Cross-Site Scriptingfontsplugin · fonts · CWE-79 | Medium5.4 | — | 0.6% | Sep 20, 2021 |
21Monitor | CVE-2024-43301No exploit | WordPress Fonts plugin <= 3.7.7 - Cross Site Request Forgery (CSRF) to Stored XSSvulnerabilityfontsplugin · fonts · CWE-352 | Medium5.4 | — | 0.2% | Aug 26, 2024 |
- CVE-2024-4330235Monitor
WordPress Fonts plugin <= 3.7.7 - Broken Access Control vulnerability
HighCVSS 8.8No exploitEPSS 0%fontsplugin · fontsNov 1, 2024
- CVE-2021-2463721Monitor
Fonts Plugin < 3.0.3 - Contributor+ Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 1%fontsplugin · fontsSep 20, 2021
- CVE-2024-4330121Monitor
WordPress Fonts plugin <= 3.7.7 - Cross Site Request Forgery (CSRF) to Stored XSSvulnerability
MediumCVSS 5.4No exploitEPSS 0%fontsplugin · fontsAug 26, 2024