Description
The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'BCF_Google_Fonts_Compatibility' class constructor function in all versions up to, and including, 2.1.16. This makes it possible for unauthenticated attackers to delete font directory and rewrite theme.json file.
Problem types
Product status
* (semver)
Timeline
| 2026-01-19: | Disclosed |
Credits
M Indra Purnama
References
www.wordfence.com/...-8811-4e7d-a16c-02f91c757705?source=cve
plugins.trac.wordpress.org/...google-fonts-compatibility.php
plugins.trac.wordpress.org/changeset/3442237/custom-fonts