Wbcom Designs – Custom Font Uploader

Wbcom Designs – Custom Font Uploader has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.3 out of 10.

The most common weakness is Missing Authorization, behind 2 of the records (100%).

Every one of the 2 issues recorded for Wbcom Designs – Custom Font Uploader has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Wbcom Designs – Custom Font Uploader is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Wbcom Designs – Custom Font Uploader vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.3

Wbcom Designs Plugins (Various Versions) - Arbitrary Plugin Installation, Activation and Deactivation

Read the full analysis

Vulnerability Records

2 records
Wbcom Designs – Custom Font Uploader banner
Latestv2.4.0

Wbcom Designs – Custom Font Uploader

wbcomdesigns

Author

wbcomdesigns

3.8(14)
76/100
Last Updated
2024-06-04 (2y ago)
Active Installs
3,000+
Downloads
63,516
Requires WP
3.0.1+
Requires PHP
7.4.0+
Tested up to
WP 6.5.10
Created
2017-06-16 (9y ago)

Description Enhance site typography easily with Google and custom fonts. You don’t need an API; you can host fonts locally. Links Plugin URL Usage Guide Easy to Use UI Intuitive interface for Google font selection with real-time preview. Effortlessly add or remove fonts with one click. Compatibility Compatible with major themes and page builders including BuddyX, Astra, Beaver Builder, Elementor, and Kirki Framework themes. Contact support@wbcomdesigns for support. Featured Theme – WordPress Theme with Exceptional BuddyPress Support FREE BuddyPress Theme: BuddyX Minimum Requirements WordPress 5.6 or greater PHP version 7.4 or greater MySQL version 5.7 or greater OR MariaDB version 10.4 or greater. Manual Installation Download and unzip the plugin. Upload to /wp-content/plugins/ directory. Activate via ‘Plugins’ menu in WordPress.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C