fi_delete_webfont AJAX action, which makes it possible for authenticated attackers with a role as low as subscriber to delete arbitrary font. Fontiran by Cadus Pro <= 2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Font Deletion
REPORT ID: bf99bdc2-bf20-4edd-9aa9-e7081ce078c5
The plugin contains a Missing Authorization vulnerability due to a missing capability check in the
You need to log in to view the vulnerability details.