LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3535 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 8, 2026

DSGVO Google Web Fonts GDPR WordPress plugin - Unrestricted File Upload

Published: April 8, 2026Updated: April 8, 2026Remote Exploitable

Overview

DSGVO Google Web Fonts GDPR WordPress plugin <= 1.1 contains an unrestricted file upload caused by missing file type validation in DSGVOGWPdownloadGoogleFonts(), letting unauthenticated attackers upload arbitrary files including PHP webshells, exploit requires specific themes.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 28.4%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can upload arbitrary files, including webshells, leading to remote code execution and full server compromise.

Mitigation

Update to the latest version of the plugin.

Social Media Activity(1 post)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 9, 2026

šŸ”“ CVE-2026-3535 - Critical (9.8) The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via ... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-3535/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-3535
Severity
Critical
CVSS Score
9.8
Type
unrestricted_file_upload
Status
unconfirmed
EPSS
28.4%
Social Posts
1

CWE

  • CWE-434

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

28.4%Probability of exploitation in the next 30 days