LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3535 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 8, 2026

DSGVO Google Web Fonts GDPR WordPress plugin - Unrestricted File Upload

Published: April 8, 2026Updated: April 8, 2026Remote Exploitable

Overview

DSGVO Google Web Fonts GDPR WordPress plugin <= 1.1 contains an unrestricted file upload caused by missing file type validation in DSGVOGWPdownloadGoogleFonts(), letting unauthenticated attackers upload arbitrary files including PHP webshells, exploit requires specific themes.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Unauthenticated attackers can upload arbitrary files, including webshells, leading to remote code execution and full server compromise.

Mitigation

Update to the latest version of the plugin.

Details

CVE ID
CVE-2026-3535
Severity
Critical
CVSS Score
9.8
Type
unrestricted_file_upload
Status
new

CWE

  • CWE-434

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H