
ACF: Google Font Selector Security & Risk Analysis
wordpress.org/plugins/acf-google-font-selector-fieldA field for Advanced Custom Fields which allows users to select Google fonts with advanced options
Is ACF: Google Font Selector Safe to Use in 2026?
Use With Caution
Score 63/100ACF: Google Font Selector has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin 'acf-google-font-selector-field' v3.0.1 exhibits a mixed security posture. While it demonstrates good practices in its handling of SQL queries by exclusively using prepared statements and avoids dangerous functions and file operations, significant concerns arise from its attack surface and output escaping. The presence of two unprotected AJAX handlers represents a direct gateway for potential malicious input, amplified by the taint analysis revealing two flows with unsanitized paths. The low percentage of properly escaped output further exacerbates this risk, making Cross-Site Scripting (XSS) a likely consequence of exploiting these unprotected entry points.
The plugin's vulnerability history, which includes one unpatched medium severity CVE related to XSS, reinforces these concerns. This indicates a recurring pattern of input validation and output sanitization weaknesses. The fact that this CVE is dated in the future (2025-04-21) might suggest a scheduled patch or a projected vulnerability discovery, but it still highlights a known security flaw that needs to be addressed. Overall, while the database interaction is secure, the lack of proper authentication on AJAX handlers, coupled with insufficient output escaping and past XSS vulnerabilities, creates a considerable risk profile.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Low percentage of properly escaped output
- Unpatched CVE (medium severity)
- Missing nonce checks on AJAX
- Missing capability checks
ACF: Google Font Selector Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ACF: Google Font Selector <= 3.0.1 - Reflected Cross-Site Scripting
ACF: Google Font Selector Code Analysis
Output Escaping
Data Flow Analysis
ACF: Google Font Selector Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
ACF: Google Font Selector Maintenance & Trust
Maintenance Signals
Community Trust
ACF: Google Font Selector Alternatives
Custom Fonts – Host Your Fonts Locally
custom-fonts
Custom Fonts is a powerful WordPress plugin that allows you to upload your own custom fonts or choose from a vast collection of Google Fonts, all host …
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
host-webfonts-local
OMGF automagically caches the Google Fonts used by your theme/plugins locally. No configuration (or brains) required!
Fonts Plugin | Use Google Fonts, Adobe Fonts or Upload Fonts
olympus-google-fonts
The easiest to customize fonts in WordPress. Optimized for Speed. 1000+ font choices. Supports Google Fonts, Adobe Fonts and Upload Fonts.
Use Any Font | Custom Font Uploader
use-any-font
Upload custom fonts with custom font uploader. Auto converts to woff2 for better performance. Self-hosted, GDPR compliant, and easy custom font plugin
Disable and Remove Google Fonts | GDPR & DSGVO friendly
disable-remove-google-fonts
Improve frontend performance by disabling Google Fonts. GDPR and DSGVO friendly.
ACF: Google Font Selector Developer Profile
12 plugins · 7K total installs
How We Detect ACF: Google Font Selector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-google-font-selector-field/css/google_font_selector.css/wp-content/plugins/acf-google-font-selector-field/js/google_font_selector.js/wp-content/plugins/acf-google-font-selector-field/acf-google_font_selector-v5.php/wp-content/plugins/acf-google-font-selector-field/acf-google_font_selector-v4.php/wp-content/plugins/acf-google-font-selector-field/js/google_font_selector.jsacf-google-font-selector-field/css/google_font_selector.css?ver=acf-google-font-selector-field/js/google_font_selector.js?ver=HTML / DOM Fingerprints
acf-google-font-selector-fieldgoogle-font-selector<!-- Web Safe Fonts Field --><!-- Enqueue Fonts Field --><!-- Default Font Field -->data-include-web-safe-fontsdata-enqueue-fontdata-default-fontacfgfs_get_font_details