CVE-2026-4657
Reported by Wordfence · Published September 10, 2026
The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin registering the control_selectors meta field with show_in_rest enabled but without a sanitize_callback, and subsequently outputting this unsanitized data directly into <style> tags on the frontend without proper escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| sunny_johal | Easy Google Fonts | 0 |
| sunny_johal | Easy Google Fonts | 0 |
Timeline
- Sep 10, 2026 EPSS Score
- Sep 10, 2026 Coalition ESS Score
- Sep 10, 2026 CVE Published
- Sep 10, 2026 CVE Updated
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score