CVE Database
/

CVE-2021-24935

Back to search

CVE-2021-24935

Published: Dec 6, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

The WP Google Fonts WordPress plugin before 3.1.5 does not escape the googlefont_ajax_name and googlefont_ajax_family parameter of the googlefont_action AJAx action (available to any authenticated user) before outputing them in attributes, leading Reflected Cross-Site Scripting issues

VendorProductVersions

Unknown

WP Google Fonts

affected
3.1.5 - < 3.1.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now