Access violation vulnerability in TK Google Fonts GDPR Compliant 2.2.11

The TK Google Fonts GDPR Compliant plugin for WordPress is insecure and could allow attackers to modify data without authorization. All versions up to and including 2.2.11 are affected by this vulnerability. Attackers with subscriber-level permissions or higher could delete any Google fonts they wanted. It’s possible that CVE-2023-5823 has been misreported as a CSRF because there was no nonce check in 2.2.11, but a capability check was added in 2.2.12.

Detected in:

TK Google Fonts GDPR Compliant fixed vulnerable versions: >= * <= 2.2.11

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.