PoC Index

CVE-2021-24977

MEDIUM 6.1EPSS 1.5%

The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any authorisation checks when assigning a font, allowing unauthenticated users to sent arbitrary CSS which will then be processed by the frontend for all users. Due to the lack of sanitisation and escaping in the backend, it could also lead to Stored XSS issues

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
1.49% chance of exploitation in the next 30 days, 72th percentile
Published
2022-02-28
Updated
2024-08-03

Proof-of-concept exploits (1)

References

Related