CVE-2026-95595: WordPress Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly disable-remove-google-fonts allows Reflected XSS.
This issue affects Disable and Remove Google Fonts | GDPR & DSGVO friendly: from n/a through 2.0.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendlyto a version that resolves this vulnerability.Fixed in 2.0.3
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation can be performed remotely with low attack complexity and requires no privileges. However, user interaction is required, meaning a victim must interact with attacker-controlled content or a crafted request.
What is the potential impact if exploitation succeeds?
The vulnerability is a reflected XSS issue with low confidentiality, integrity, and availability impact in the CVSS vector. The scope is changed, indicating the vulnerable component could affect another security authority or context.
Which plugin versions are affected?
The issue affects Fontsplugin Disable and Remove Google Fonts | GDPR & DSGVO friendly through version 2.0.2. No fixed version is provided in the available data.