Advanced Typekit
Advanced Typekit has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Advanced Typekit has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by SOPROBRO. Advanced Typekit is installed on roughly 50 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 3.1.4.
CVE-2025-31622Advanced Typekit <= 1.0.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Advanced Typekit
Author
Utkarsh Kukreti
This plugin allows you to add Typekit fonts to your site, by targetting them to specific elements using css selectors from the admin panel. It uses the new Typekit API to fetch fonts’ info from your account. Enter your Typekit API key from Settings -> Advanced Typekit, and the plugin will fetch all the fonts you’ve added to your kit. Enter the css selectors you want to target for each font, along with any extra css. The extra css is only applied when the browser has loaded the font. This plugin uses the Google WebFont Loader to load your Typekit fonts. Click on the Screenshot link above to preview the plugins admin page. Note: You need PHP5 on your server, and a Typekit account to use this plugin.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C