Input validation vulnerability in CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts 4.2

The CITS Support plugin for WordPress allows users to upload svg, webp, and TTF/OTF files and use custom fonts on their website. However, it has a security vulnerability called Cross-Site Request Forgery, which affects all versions up to 4.2. This means that if a hacker can trick a site administrator into clicking on a link, they can delete font assignments without proper validation. This puts the website at risk of unauthorized changes.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.