Stored Cross-Site Scripting in Easy Google Fonts Plugin for WordPress
CVE-2026-4657
6.4MEDIUM
What is CVE-2026-4657?
The Easy Google Fonts plugin for WordPress is subject to Stored Cross-Site Scripting due to the registration of the control_selectors meta field with show_in_rest enabled and lacking a sanitize_callback. This oversight allows authenticated users with Author-level access and higher to insert arbitrary scripts into pages via unsanitized data output directly into tags. As a result, any user who visits the affected pages may have their session compromised or be subject to unwanted actions initiated by the attacker.
Affected Version(s)
Easy Google Fonts 0 <= 2.0.4