Junglewise Threat Intelligence

CVE-2026-3535: mlfactory DSGVO Google Web Fonts GDPR arbitrary file upload

CVE-2026-3535 · Severity: critical · CVSS 9.8 · Published 2026-04-08

Executive brief

The DSGVO Google Web Fonts GDPR plugin for WordPress, which helps websites comply with privacy laws by hosting fonts locally, contains a critical security flaw. An unauthenticated attacker can trick the plugin into downloading malicious files, such as web shells, directly onto the web server. This could allow an attacker to take complete control of the website, steal sensitive data, or disrupt operations.

Technical details

The vulnerability exists in the DSGVOGWPdownloadGoogleFonts() function due to a lack of file type validation. This function is hooked into wp_ajax_nopriv_, making it accessible to unauthenticated users. An attacker can provide a URL to a malicious CSS file; the plugin then parses this file, extracts URLs for 'fonts', and downloads those files to a public directory. By including a URL to a PHP shell within the malicious CSS, an attacker can achieve remote code execution. Note that the exploitability is limited to sites using specific themes such as twentyfifteen, twentyseventeen, storefront, salient, or shapely.

Affected products

  • mlfactory DSGVO Google Web Fonts GDPR <= 1.1

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory

References