
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14351 is a Missing Authorization vulnerability in the Custom Fonts – Host Your Fonts Locally WordPress plugin that allows unauthenticated attackers to delete font directories and overwrite the theme.json file. It affects all versions up to and including 2.1.16. The vulnerability was published on January 19–20, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is a missing capability check (CWE-862) in the BCF_Google_Fonts_Compatibility class constructor function within the plugin file includes/class-bcf-google-fonts-compatibility.php (around line 88). Because the constructor executes privileged operations — deleting the font directory and rewriting theme.json — without verifying whether the caller has appropriate WordPress capabilities, any unauthenticated network request that triggers this constructor can invoke these destructive actions. No authentication, elevated privileges, or user interaction is required, making the attack vector entirely network-accessible with low complexity (Wordfence, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to delete the site's font directory and arbitrarily rewrite the WordPress theme.json configuration file, corrupting the site's visual theme and styling. While there is no direct confidentiality impact (no data exfiltration), the integrity of the WordPress theme is compromised, which could be leveraged to deface the site or inject malicious content into theme configuration. Availability is not directly impacted per the CVSS assessment, though theme corruption may render the site visually broken for end users (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.045%, indicating a low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The low barrier to exploitation (no authentication required, network-accessible) does increase theoretical risk, but the limited impact scope keeps overall exploitability concern moderate (Wordfence).
wp-content/plugins/custom-fonts/.BCF_Google_Fonts_Compatibility class constructor to be invoked — this may occur via a specific REST API endpoint, admin-ajax action, or page load that initializes the class without an authentication gate.theme.json file, potentially injecting attacker-controlled theme configuration values that alter site appearance or embed malicious data (Wordfence, WordPress Trac).wp-content/uploads/custom-fonts/ or similar); unexpected modification timestamps on theme.json in the active theme directory.BCF_Google_Fonts_Compatibility class (e.g., specific REST API routes or admin-ajax calls associated with the plugin); repeated requests from a single IP targeting these endpoints.wp-content/debug.log) showing unexpected class instantiation or file write operations from the custom-fonts plugin without an authenticated session context.The vulnerability was patched in the plugin changeset 3442237, which adds the missing capability check. Site administrators should update the Custom Fonts – Host Your Fonts Locally plugin to version 2.1.17 or later immediately. As a temporary workaround, the plugin can be deactivated until the update is applied. Web application firewalls (WAFs) such as Wordfence can provide virtual patching to block exploitation attempts against unpatched sites (Wordfence, WordPress Trac).
Sucuri included this vulnerability in their January 2026 vulnerability patch roundup, noting it as part of a broader set of WordPress plugin issues requiring attention (Sucuri Blog). Coverage was otherwise limited to automated vulnerability tracking platforms and security feeds, with no significant researcher commentary or widespread media coverage observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."