Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-3535

37
FAUCET Score

OVERVIEW The DSGVO Google Web Fonts GDPR plugin for WordPress versions 1.1 and earlier contains an arbitrary file upload vulnerability in the DSGVOGWPdownloadGoogleFonts() function. The vulnerability exists because the plugin fails to validate file types when downloading files from user-supplied URLs. The vulnerable function is exposed via an unauthenticated AJAX hook, allowing any visitor to trigger the upload mechanism. Exploitation requires the target site to use one of six specific WordPress themes: twentyfifteen, twentyseventeen, twentysixteen, storefront, salient, or shapely. SEVERITY This vulnerability carries a CVSS 3.1 score of 9.8 CRITICAL with a network-based attack vector requiring no authentication, no special configuration, and no user interaction. An unauthenticated attacker can exploit this remotely to upload arbitrary files, including PHP webshells, to publicly accessible directories on the affected server. The vulnerability enables remote code execution with full system compromise potential, affecting confidentiality, integrity, and availability. The FAUCET Risk Score of 55.0/100 indicates moderate additional risk factors beyond the base CVSS assessment. EXPLOITATION STATUS This vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.0034 indicates this threat ranks below average for real-world exploitation probability. There is no indication of publicly available exploit code, and community attention appears limited, suggesting organizations should prioritize patching based on plugin installation prevalence rather than immediate threat response.

Impacted Technologies

VendorProductVersion(s)CPE
MlfactoryDSGVO Google Web Fonts GDPR
>= 0, <= 1.1CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.92%
Probability of exploitation in next 30 days
EPSS Percentile
56.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0092 is in the 42nd percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/dsgvo-google-web-fonts-gdpr/tags/1.1/dsgvo-google-web-fonts-gdpr.php
plugins.trac.wordpress.org / browser/dsgvo-google-web-fonts-gdpr/tags/1.1/dsgvo-google-web-fonts-gdpr.php
plugins.trac.wordpress.org / browser/dsgvo-google-web-fonts-gdpr/trunk/dsgvo-google-web-fonts-gdpr.php
plugins.trac.wordpress.org / browser/dsgvo-google-web-fonts-gdpr/trunk/dsgvo-google-web-fonts-gdpr.php
wordfence.com / threat-intel/vulnerabilities/id/6203ffaf-5efd-4c66-85f0-cc3a05a03084