Input validation vulnerability in Elegant Custom Fonts 1.0

The Elegant Custom Fonts plugin for WordPress has a security vulnerability in versions up to 1.0. This vulnerability could allow attackers to make changes to the plugin’s settings without needing to be logged in. This could happen if the attacker can get a site administrator to click on a link or do another action. This security issue is caused by the lack of nonce validation on the admin_page function.

Detected in:

Elegant Custom Fonts open vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.