3 Mar 2022

Vulnerability Details: Cross-Site Request Forgery (CSRF) in Use Any Font

As often is the case, WPScan recently released a mess of a report of a claimed vulnerability in WordPress plugin Use Any Font. The report both claims that part of the issue exists in versions after it had already been resolved, but also claims the issue has been fixed, despite not being fully resolved. We had warned our customers about the original form of the vulnerability back in 2017.


[Read more]

20 Oct 2017

Vulnerability Details: Cross-Site Request Forgery (CSRF)/Cross-Site Scripting (XSS) Vulnerability in Use Any Font

Recently the web scanner service Detectify has been vaguely disclosing minor vulnerabilities in a number of WordPress plugins. It seems like they are aware that they could notify the developer of these, but usually haven’t been doing it. One of the more recent batch was a cross-site request forgery (CSRF) vulnerability in the plugin Use Any Font.


[Read more]