Cross-Site Request Forgery Vulnerability in Font Pairing Preview Plugin for WordPress
CVE-2026-1086

4.3MEDIUM

What is CVE-2026-1086?

The Font Pairing Preview Plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit missing nonce validation in the settings update function. This flaw permits attackers to manipulate font pairing settings by tricking a site administrator into performing unintended actions, creating a significant security risk for users. To safeguard your website, it is crucial to update to the latest plugin version and implement security best practices.

Affected Version(s)

Font Pairing Preview For Landing Pages 0 <= 1.3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Afnaan
.