← Back

Flex Local Fonts

flex_local_fonts

Vendor: Flex Local Fonts Project • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Flex Local Fonts Project
1Flex Local Fonts
Jun 17, 2026
Dec 13, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html c...Show more
The Flex Local Fonts WordPress plugin through 1.0.0 does not escape the Class Name field when adding a font, which could allow hight privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.Show less