CVE-2024-33942 MEDIUM

CVE-2024-33942: WordPress Google Typography plugin <= 1.1.2 - Broken Access Control vulnerability

Vendor Eric Alli
Product Google Typography
Weakness CWE-862 · Missing authorization
Published May 2, 2024
Last update April 28, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2.

Explanation of Vulnerability in Simple Terms

02Summary

Google Typography through version 1.1.2 fails to properly check user permissions before allowing modifications to typography settings. An authenticated user with low privileges can alter typography configurations that should be restricted to administrators. The vulnerability does not expose sensitive data or cause service disruption, but allows unauthorized changes to site appearance and styling.

What an attacker can do

03Attacker Capabilities

Modify typography settings without proper authorization.

Potential impact on your site

04Site Impact

Unauthorized users can change site typography and styling settings intended for administrators only.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege authenticated account on the site.

Key dates

06Disclosure timeline

May 2, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE