CVE-2015-7683: Font Project Font

Medium severity, CVSS 4.0. EPSS: 5% chance of exploitation in the next 30 days.

Absolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administrators to read arbitrary files via a full pathname in the url parameter to AjaxProxy.php.

Affected products

Published 2015-10-16. Last modified 2026-06-17.