Cross-Site Request Forgery Vulnerability in Font Pairing Preview Plugin for WordPress
CVE-2026-1086
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 March 2026
What is CVE-2026-1086?
The Font Pairing Preview Plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit missing nonce validation in the settings update function. This flaw permits attackers to manipulate font pairing settings by tricking a site administrator into performing unintended actions, creating a significant security risk for users. To safeguard your website, it is crucial to update to the latest plugin version and implement security best practices.
Affected Version(s)
Font Pairing Preview For Landing Pages 0 <= 1.3