Detects WordPress instances with the DSGVO Google Web Fonts GDPR plugin installed (all versions through 1.1). The plugin registers an unauthenticated AJAX action (DSGVOGWPdownloadGoogleFonts) that fetches attacker-controlled URLs via wp_remote_get() and saves files to a public directory without any file type validation. An attacker can upload PHP webshells and achieve remote code execution. No patch exists — the plugin was closed on WordPress.org. Remove it immediately.
Is your app exploitable through CVE-2026-3535?
Scan your domain free