All verified exploits

CVE-2026-3535 Unauthenticated Arbitrary File Upload via DSGVO Google Web Fonts GDPR Plugin

Deterministic critical WordPress Added cve-verified-cve-2026-3535

Detects WordPress instances with the DSGVO Google Web Fonts GDPR plugin installed (all versions through 1.1). The plugin registers an unauthenticated AJAX action (DSGVOGWPdownloadGoogleFonts) that fetches attacker-controlled URLs via wp_remote_get() and saves files to a public directory without any file type validation. An attacker can upload PHP webshells and achieve remote code execution. No patch exists — the plugin was closed on WordPress.org. Remove it immediately.

Related WordPress exploits

Is your app exploitable through CVE-2026-3535?

Scan your domain free