Impact
The vulnerability resides in the Easy Google Fonts plugin where the control_selectors meta field is registered with REST visibility but lacks any sanitization. When the plugin outputs this metadata inside <style> tags on the site without escaping, an attacker with at least Author privilege can inject arbitrary JavaScript. The injected scripts would execute on any visitor to the affected page, enabling session hijacking, defacement, or phishing attacks.
Affected Systems
All instances of the Easy Google Fonts WordPress plugin up to and including version 2.0.4 are vulnerable. The affected product is the plugin from the developer Sunny_Johal. Any WordPress site running these plugin versions is at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates significant impact, while the EPSS score is not available, so current exploitation probability is unknown. This vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires the attacker to be authenticated with Author-level access or higher, which suggests the threat vector is local or internal. Attackers can leverage the WordPress administrative interface to modify the meta field, then any visitor to the compromised page will trigger the injected script.
OpenCVE Enrichment