Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS.

This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2.
Published: 2026-10-07
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross-site scripting
Action: Apply patch
AI Analysis

Impact

The vulnerability is a reflected cross-site scripting flaw caused by improper neutralization of input during web page generation. An attacker could inject malicious JavaScript that would execute in any visitor’s browser, enabling theft of credentials, session tokens, or impersonation of the user. This flaw is classified as CWE‑79 and provides unescaped user input to the output.

Affected Systems

The affected product is the WordPress plugin "Disable and Remove Google Fonts | GDPR & DSGVO friendly" version 2.0.2 and all earlier releases. The plugin is delivered via the WordPress.org repository and is widely used on sites running WordPress. The vendor recommends updating to 2.0.3 or later to eliminate the vulnerability.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity threat, and while the EPSS score is not available, the lack of a KEV listing suggests no large-scale exploitation has been reported yet. The attack can be performed remotely by sending a crafted URL containing malicious payload to any visitor, without requiring authentication or privileged access. Given the widespread use of WordPress and the plugin, the potential impact to confidentiality, integrity, and availability is significant for sites that rely on this feature.

Generated by OpenCVE AI on October 7, 2026 at 18:32 UTC.

Remediation

Vendor Solution

Update the WordPress Disable and Remove Google Fonts | GDPR & DSGVO friendly Plugin to the latest available version (at least 2.0.3).


OpenCVE Recommended Actions

  • Update the plugin to version 2.0.3 or later.
  • If an immediate update is not possible, temporarily disable or uninstall the plugin to remove the vulnerable code.
  • Apply a web application firewall rule that blocks or sanitizes query parameters used by the plugin to prevent XSS until the patch is applied.

Generated by OpenCVE AI on October 7, 2026 at 18:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS. This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2.
Title WordPress Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability
First Time appeared Fontsplugin
Fontsplugin disable And Remove Google Fonts Gdpr Dsgvo Friendly
Weaknesses CWE-79
CPEs cpe:2.3:a:fontsplugin:disable_and_remove_google_fonts_gdpr_dsgvo_friendly:*:*:*:*:*:*:*:*
Vendors & Products Fontsplugin
Fontsplugin disable And Remove Google Fonts Gdpr Dsgvo Friendly
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Fontsplugin Disable And Remove Google Fonts Gdpr Dsgvo Friendly
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-07T19:23:46.144Z

Reserved: 2026-09-22T09:18:20.379Z

Link: CVE-2026-95595

cve-icon Vulnrichment

Updated: 2026-10-07T19:18:41.971Z

cve-icon NVD

Status : Received

Published: 2026-10-07T17:17:03.923

Modified: 2026-10-07T20:17:15.650

Link: CVE-2026-95595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T18:45:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')