First published: Tue Apr 01 2025(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wisdomlogix Solutions Pvt. Ltd. Fonts Manager | Custom Fonts allows Reflected XSS. This issue affects Fonts Manager | Custom Fonts: from n/a through 1.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wisdomlogix Solutions Fonts Manager | Custom Fonts | <=1.2 | |
WordPress Fonts Manager | <=1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31578 is classified as a moderate severity vulnerability due to its potential to enable reflected Cross-site Scripting (XSS) attacks.
To remediate CVE-2025-31578, users should upgrade the Fonts Manager | Custom Fonts plugin to version 1.2 or later, if available.
CVE-2025-31578 is associated with reflected XSS attacks which can allow an attacker to execute malicious scripts in users' browsers.
CVE-2025-31578 affects all versions of the Fonts Manager | Custom Fonts plugin up to and including version 1.2.
If you are unable to update, consider disabling the plugin or implementing web application firewall rules to mitigate potential exploitation of CVE-2025-31578.