Fonto – Custom Web Fonts Manager

Fonto – Custom Web Fonts Manager has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Path Traversal.

Every one of the 2 issues recorded for Fonto – Custom Web Fonts Manager has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. Fonto – Custom Web Fonts Manager is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
6.5/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Fonto – Custom Web Fonts Manager vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.5CVE-2025-31827

Fonto <= 1.2.2 - Authenticated (Author+) Arbitrary File Download

Read the full analysis

Vulnerability Records

2 records
Fonto – Custom Web Fonts Manager banner
Latestv1.2.4

Fonto – Custom Web Fonts Manager

vlad.olaru

Author

vlad.olaru

3.0(4)
60/100
Last Updated
2026-08-13 (1mo ago)
Active Installs
2,000+
Downloads
42,667
Requires WP
5.9.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2016-06-19 (10y ago)

Fonto is a custom fonts management plugin that will seamlessly integrate with the WordPress editor, allowing you to get right to using your fancy free or premium fonts. It is built to work with pretty much any configuration font vendors offer (like Typekit, Fonts.com, MyFonts.com, Google Fonts), either by allowing them to serve the fonts via an embed code or by self-hosting the font files. Plus, we’ve integrated Fonto with our Customify and Style Manager plugins to make it even smoother to control your site’s general typography. Credits CMB2 Metaboxes, custom fields library – License: GPLv2 or later CMB2 Conditionals plugin for CMB2 – License: GPLv2 or later

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C