Description
Cross-Site Request Forgery (CSRF) vulnerability in Uzair Easyfonts easyfonts allows Cross Site Request Forgery.This issue affects Easyfonts: from n/a through <= 1.1.2.
Published: 2025-04-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Easyfonts plugin for WordPress enables Cross‑Site Request Forgery. An attacker can supply a specially crafted request that is accepted by the plugin without proper validation, allowing the attacker to perform actions on behalf of an authenticated user. This weakness permits malicious manipulation of data or settings controlled by the victim’s WordPress account, potentially altering site content or configuration.

Affected Systems

This vulnerability affects the Uzair Easyfonts plugin for WordPress at versions 1.1.2 and earlier. No CPE strings are listed, but the CNA product name provides the necessary vendor information for patching or disabling the plugin.

Risk and Exploitability

The CVSS score of 4.3 places the issue in the low–medium severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been widely exploited yet. Likely attack vectors involve a user visiting a crafted URL or page that triggers the vulnerable request while the user remains authenticated to the site. The required conditions are the presence of a logged‑in WordPress user with sufficient privileges and exploitation of the unprotected action in Easyfonts.

Generated by OpenCVE AI on April 30, 2026 at 23:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the plugin repository for an updated version of Easyfonts that addresses the CSRF issue and upgrade once available
  • If no patch is offered, permanently disable or uninstall the Easyfonts plugin to eliminate the attack surface
  • Monitor site logs for unexpected requests to Easyfonts actions and audit user permissions to detect potential CSRF attempts

Generated by OpenCVE AI on April 30, 2026 at 23:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10659 Cross-Site Request Forgery (CSRF) vulnerability in Uzair Easyfonts allows Cross Site Request Forgery. This issue affects Easyfonts: from n/a through 1.1.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Uzair Easyfonts allows Cross Site Request Forgery. This issue affects Easyfonts: from n/a through 1.1.2. Cross-Site Request Forgery (CSRF) vulnerability in Uzair Easyfonts easyfonts allows Cross Site Request Forgery.This issue affects Easyfonts: from n/a through <= 1.1.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 09 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 16:30:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Uzair Easyfonts allows Cross Site Request Forgery. This issue affects Easyfonts: from n/a through 1.1.2.
Title WordPress Easyfonts plugin <= 1.1.2 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:03.365Z

Reserved: 2025-03-26T09:22:56.081Z

Link: CVE-2025-31005

cve-icon Vulnrichment

Updated: 2025-04-09T17:53:19.484Z

cve-icon NVD

Status : Deferred

Published: 2025-04-09T17:15:33.233

Modified: 2026-04-23T15:27:31.040

Link: CVE-2025-31005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:45:03Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)