Executive brief
The TypeSquare Webfonts for ConoHa plugin for WordPress, which allows site owners to manage custom web fonts, contains a security flaw that allows low-level users to change site-wide font settings. An attacker with a basic account (such as a subscriber) could modify how fonts are displayed across the entire website. This could lead to unauthorized changes to the site's appearance or the disabling of specific font features.
Technical details
The TypeSquare Webfonts for ConoHa plugin for WordPress suffers from a missing authorization check (CWE-862) in its administrative handling logic. Authenticated attackers with subscriber-level permissions or higher can modify sensitive plugin options, such as 'typesquare_auth', 'show_post_form', and 'typesquare_fonttheme', by sending a crafted POST request to any wp-admin page. Additionally, certain configuration branches (fontThemeUseType values 1 and 3) lack nonce verification, making them susceptible to Cross-Site Request Forgery (CSRF) attacks. This allows an attacker to manipulate the site's font configuration without proper administrative privileges.
Affected products
- TypeSquare TypeSquare Webfonts for ConoHa Up to, and including, 2.0.4
Timeline
- 2026-05-20: disclosed: Initial publication of the CVE record.
References
- https://plugins.trac.wordpress.org/browser/ts-webfonts-for-conoha/tags/2.0.4/inc/class/class.auth.php
- https://plugins.trac.wordpress.org/browser/ts-webfonts-for-conoha/tags/2.0.4/typesquare-admin.php
- https://plugins.trac.wordpress.org/browser/ts-webfonts-for-conoha/tags/2.0.4/typesquare-admin.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/88002a25-6890-4f8b-8a11-239b59d56672?source=cve