Fonto – Custom Web Fonts Manager
Fonto – Custom Web Fonts Manager has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.5, and the most serious one scores 6.5 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Path Traversal.
Every one of the 2 issues recorded for Fonto – Custom Web Fonts Manager has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Fonto – Custom Web Fonts Manager is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2025-31827Fonto <= 1.2.2 - Authenticated (Author+) Arbitrary File Download
Read the full analysisVulnerability Records

Fonto – Custom Web Fonts Manager
Author
vlad.olaru
Fonto is a custom fonts management plugin that will seamlessly integrate with the WordPress editor, allowing you to get right to using your fancy free or premium fonts. It is built to work with pretty much any configuration font vendors offer (like Typekit, Fonts.com, MyFonts.com, Google Fonts), either by allowing them to serve the fonts via an embed code or by self-hosting the font files. Plus, we’ve integrated Fonto with our Customify and Style Manager plugins to make it even smoother to control your site’s general typography. Credits CMB2 Metaboxes, custom fields library – License: GPLv2 or later CMB2 Conditionals plugin for CMB2 – License: GPLv2 or later
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C