• Vulnerability: XSS
  • Affected Software: Font_Organizer (30,000+ active installations)
  • Affected Version: 2.1.1
  • Patched Version: none
  • Risk: Medium
  • Vendor Contacted: 10/25/2018
  • Vendor Fix: none
  • Public Disclosure: 02/05/2019

6.1 Medium CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N


The Font_Organizer WordPress plugin is vulnerable to reflected XSS as it echoes the manage_font_id parameter without proper encoding.

Successful exploitation allows an attacker to execute JavaScript in the context of the application in the name of an attacked user. This in turn enables an attacker to bypass CSRF protection and thus perform any actions the legitimate user can perform, as well as read data which the user can access.

Proof of Concept'"><img src=x onerror=alert(1)>&page=font-setting-admin
<input type="hidden" name="font_id" value="<?php echo $_GET['manage_font_id']; ?>">
<input type="hidden" name="manage_font_id" value="<?php echo $_GET['manage_font_id']; ?>">
  • 10/25/2018 Sent advisory (no response)
  • 02/05/2019 Disclosure