Input validation vulnerability in WP Google Fonts 3.1.4

The WP Google Fonts plugin for WordPress is vulnerable to a security issue called Reflected Cross-Site Scripting. This issue affects versions up to and including 3.1.3 of the plugin. It is caused by the plugin not properly checking and sanitizing input, or properly escaping output. This means that outside attackers could potentially inject malicious code like web scripts into pages, and if the user clicks on a link, the code could be executed.

Detected in:

WP Google Fonts open vulnerable versions: >= * < 3.1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.