VYPR

Custom Fonts – Host Your Fonts Locally

by Brainstormforce

CVEs (1)

  • CVE-2025-14351MedJan 20, 2026
    risk 0.34cvss 5.3epss 0.00

    The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'BCF_Google_Fonts_Compatibility' class constructor function in all versions up to, and including, 2.1.16. This makes it possible for unauthenticated attackers to delete font directory and rewrite theme.json file.