The TK Google Fonts plugin for WordPress is susceptible to unauthorized changes to data in all versions up to 2.2.11. This means that people with subscriber-level permissions or higher can add whatever Google Fonts they want. This issue may have been reported as a Cross-Site Request Forgery (CSRF) but the problem is actually a missing capability check, which was fixed in 2.2.12.