Impact
The vulnerability is a reflected cross-site scripting flaw caused by improper neutralization of input during web page generation. An attacker could inject malicious JavaScript that would execute in any visitor’s browser, enabling theft of credentials, session tokens, or impersonation of the user. This flaw is classified as CWE‑79 and provides unescaped user input to the output.
Affected Systems
The affected product is the WordPress plugin "Disable and Remove Google Fonts | GDPR & DSGVO friendly" version 2.0.2 and all earlier releases. The plugin is delivered via the WordPress.org repository and is widely used on sites running WordPress. The vendor recommends updating to 2.0.3 or later to eliminate the vulnerability.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity threat, and while the EPSS score is not available, the lack of a KEV listing suggests no large-scale exploitation has been reported yet. The attack can be performed remotely by sending a crafted URL containing malicious payload to any visitor, without requiring authentication or privileged access. Given the widespread use of WordPress and the plugin, the potential impact to confidentiality, integrity, and availability is significant for sites that rely on this feature.
OpenCVE Enrichment