Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Flex Local Fonts Project Subscribe
Filtered by product Flex Local Fonts
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24782 1 Flex Local Fonts Project 1 Flex Local Fonts 2021-12-15 3.5 LOW 4.8 MEDIUM
The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.