plugin

Dsgvo Google Web Fonts Gdpr Vulnerabilities

1 known security issue reported for the Dsgvo Google Web Fonts Gdpr WordPress plugin. Most recent disclosed Apr 7, 2026.

1 critical

Running Dsgvo Google Web Fonts Gdpr on your site? Check whether your installed version is affected.

Scan your site free

DSGVO Google Web Fonts GDPR <= 1.1 - Unauthenticated Arbitrary File Upload via 'fonturl' Parameter

critical

The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication. It fetches a user-...

CVSS:
9.8
Affected:
up to 1.1
Fix:
No patched version reported
Disclosed:
Apr 7, 2026

CVE-2026-3535 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database