VDB

CVE-2026-4657

CVE-2026-4657 PUBLISHED CVSS 6.4 MEDIUM

Reported by Wordfence · Published September 10, 2026

The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin registering the control_selectors meta field with show_in_rest enabled but without a sanitize_callback, and subsequently outputting this unsanitized data directly into <style> tags on the frontend without proper escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Risk Scores

CVSS 3.1
6.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Affected Products

VendorProductVersions
sunny_johalEasy Google Fonts0
sunny_johalEasy Google Fonts0

Timeline

  • Sep 10, 2026 EPSS Score
  • Sep 10, 2026 Coalition ESS Score
  • Sep 10, 2026 CVE Published
  • Sep 10, 2026 CVE Updated
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›