Wbcom Designs – Custom Font Uploader
Wbcom Designs – Custom Font Uploader has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 6.3 out of 10.
The most common weakness is Missing Authorization, behind 2 of the records (100%).
Every one of the 2 issues recorded for Wbcom Designs – Custom Font Uploader has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Wbcom Designs – Custom Font Uploader is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.5.10.
Wbcom Designs Plugins (Various Versions) - Arbitrary Plugin Installation, Activation and Deactivation
Read the full analysisVulnerability Records

Wbcom Designs – Custom Font Uploader
Author
wbcomdesigns
Description Enhance site typography easily with Google and custom fonts. You don’t need an API; you can host fonts locally. Links Plugin URL Usage Guide Easy to Use UI Intuitive interface for Google font selection with real-time preview. Effortlessly add or remove fonts with one click. Compatibility Compatible with major themes and page builders including BuddyX, Astra, Beaver Builder, Elementor, and Kirki Framework themes. Contact support@wbcomdesigns for support. Featured Theme – WordPress Theme with Exceptional BuddyPress Support FREE BuddyPress Theme: BuddyX Minimum Requirements WordPress 5.6 or greater PHP version 7.4 or greater MySQL version 5.7 or greater OR MariaDB version 10.4 or greater. Manual Installation Download and unzip the plugin. Upload to /wp-content/plugins/ directory. Activate via ‘Plugins’ menu in WordPress.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C