Impact
The Fonts Manager | Custom Fonts plugin for WordPress is vulnerable to a time‑based SQL injection through the fmcfIdSelectedFnt parameter, allowing an attacker to inject arbitrary SQL statements. This weakness is based on insufficient input escaping and lack of prepared statements. The primary impact is the ability to read sensitive information from the database, leading to potential data compromise. The vulnerability is identified as CWE‑89.
Affected Systems
WordPress sites running the Fonts Manager | Custom Fonts plugin by wisdomlogix, versions up to and including 1.2, are affected. No later version is specified as a fix in the available data. Site administrators should check the plugin version and remove or update the plugin if the version is within the vulnerable range.
Risk and Exploitability
The CVSS score of 7.5 indicates a high-impact vulnerability. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, implying it has not yet been exploited in the wild. The attack vector is unauthenticated, meaning any web visitor can exploit the flaw. If successfully exploited, the attacker can retrieve confidential database contents without authentication, posing a significant threat to data confidentiality.
OpenCVE Enrichment