Access violation vulnerability in TK Google Fonts GDPR Compliant 2.2.11

The TK Google Fonts plugin for WordPress is susceptible to unauthorized changes to data in all versions up to 2.2.11. This means that people with subscriber-level permissions or higher can add whatever Google Fonts they want. This issue may have been reported as a Cross-Site Request Forgery (CSRF) but the problem is actually a missing capability check, which was fixed in 2.2.12.

Detected in:

TK Google Fonts GDPR Compliant fixed vulnerable versions: >= * <= 2.2.11

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.