CVE-2024-1332: Custom Fonts – Host Your Fonts Locally <= 2.1.4 - Authenticated (Author+) Stored Cross-Site Scripting
The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg file upload in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author level or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1332?
CVE-2024-1332 is classified as a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-1332?
To fix CVE-2024-1332, update the Custom Fonts – Host Your Fonts Locally plugin to version 2.1.5 or later.
Who is affected by CVE-2024-1332?
All installations of the Custom Fonts – Host Your Fonts Locally plugin for WordPress up to and including version 2.1.4 are affected by CVE-2024-1332.
What kind of attack does CVE-2024-1332 allow?
CVE-2024-1332 allows authenticated attackers to perform Stored Cross-Site Scripting via SVG file uploads.
What does insufficient input sanitization mean in CVE-2024-1332?
Insufficient input sanitization in CVE-2024-1332 means that the plugin does not properly validate or clean user inputs before storing them, leading to potential security risks.