CVE-2025-39382
CVSS 3.1 Score 7.1 of 10 (high)
Details
Summary
CVE-2025-39382 is a Cross-Site Scripting (XSS) vulnerability affecting the ACF: Google Font Selector plugin for WordPress. The flaw, specifically an improper neutralization of input during web page generation, allows an attacker to inject malicious scripts into web pages viewed by other users. Successful exploitation of this vulnerability can lead to the theft of user data or the execution of unauthorized actions. The issue affects all versions of the plugin from the initial release through 3.0.1. It is strongly recommended that users upgrade to a secure version of the plugin as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.