Impact
The Custom Fonts – Host Your Fonts Locally WordPress plugin is vulnerable in all versions up to and including 2.1.16 due to a missing capability check in the BCF_Google_Fonts_Compatibility class constructor, which allows any unauthenticated user to trigger font directory deletion and overwrite the theme.json file. This flaw results in loss of font assets, potential corruption of theme settings, and the inability to access the site without manual restoration. The weakness is classified as a missing authorization issue (CWE-862).
Affected Systems
BRAINSTORMFORCE Custom Fonts – Host Your Fonts Locally plugin on WordPress installations running any version up to and including 2.1.16 is affected; newer releases are not mentioned as vulnerable.
Risk and Exploitability
The risk is moderate with a CVSS score of 5.3 and an EPSS score of less than 1%, indicating low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw remotely by simply loading the plugin’s constructor via a web request, allowing unauthenticated deletion of critical font resources and theme configuration.
OpenCVE Enrichment