PT-2026-31095 · Mlfactory · Dsgvo Google Web Fonts Gdpr

Nabil Irawan

·

Published

2026-04-08

·

Updated

2026-04-08

·

CVE-2026-3535

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the DSGVOGWPdownloadGoogleFonts() function in all versions up to, and including, 1.1. The function is exposed via a wp ajax nopriv hook, requiring no authentication. It fetches a user-supplied URL as a CSS file, extracts URLs from its content, and downloads those files to a publicly accessible directory without validating the file type. This makes it possible for unauthenticated attackers to upload arbitrary files including PHP webshells, leading to remote code execution. The exploit requires the site to use one of a handful of specific themes (twentyfifteen, twentyseventeen, twentysixteen, storefront, salient, or shapely).

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-3535

Affected Products

Dsgvo Google Web Fonts Gdpr