OVERVIEW The DSGVO Google Web Fonts GDPR plugin for WordPress versions 1.1 and earlier contains an arbitrary file upload vulnerability in the DSGVOGWPdownloadGoogleFonts() function. The vulnerability exists because the plugin fails to validate file types when downloading files from user-supplied URLs. The vulnerable function is exposed via an unauthenticated AJAX hook, allowing any visitor to trigger the upload mechanism. Exploitation requires the target site to use one of six specific WordPress themes: twentyfifteen, twentyseventeen, twentysixteen, storefront, salient, or shapely. SEVERITY This vulnerability carries a CVSS 3.1 score of 9.8 CRITICAL with a network-based attack vector requiring no authentication, no special configuration, and no user interaction. An unauthenticated attacker can exploit this remotely to upload arbitrary files, including PHP webshells, to publicly accessible directories on the affected server. The vulnerability enables remote code execution with full system compromise potential, affecting confidentiality, integrity, and availability. The FAUCET Risk Score of 55.0/100 indicates moderate additional risk factors beyond the base CVSS assessment. EXPLOITATION STATUS This vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.0034 indicates this threat ranks below average for real-world exploitation probability. There is no indication of publicly available exploit code, and community attention appears limited, suggesting organizations should prioritize patching based on plugin installation prevalence rather than immediate threat response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mlfactory | DSGVO Google Web Fonts GDPR | >= 0, <= 1.1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.