PT-2026-26815 · WordPress · Fonts Manager | Custom Fonts
CVE-2026-1800
·
Publicado
2026-03-21
·
Atualizado
2026-03-21
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Fonts Manager | Custom Fonts plugin for WordPress versions prior to 1.3
Description
The Fonts Manager | Custom Fonts plugin for WordPress is susceptible to time-based SQL Injection. This is due to inadequate escaping of user-supplied input and insufficient preparation of existing SQL queries. The
fmcfIdSelectedFnt parameter is the point of entry for this issue. Successful exploitation allows unauthenticated attackers to append additional SQL queries, potentially extracting sensitive information from the database.Recommendations
Update to version 1.3 or later.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fonts Manager | Custom Fonts