← WordPress Vulnerabilities
WordPress security by component

CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts

CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Mar 22, 2025; the highest CVE/CNA score is 4.3.

Plugin slug: cits-support-svg-webp-media-upload

CVE-2025-0807: CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts: Cross-site request forgery

CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.

PublishedMar 22, 2025
Safe version guidanceSee mitigation notes
Safe version
Mar 22, 2025 CVE-2025-0807
CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts: Cross-site request forgery
CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Mar 22, 2025 CVE-2024-13768
CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts: Cross-site request forgery
CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending