CVE-2026-3535Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` function in all versions up to, and including, 1.1. The function is exposed via a `wp_ajax_nopriv_` hook, requiring no authentication. It fetches a user-supplied URL as a CSS file, extracts URLs from its content, and downloads those files to a publicly accessible directory without validating the file type. This makes it possible for unauthenticated attackers to upload arbitrary files including PHP webshells, leading to remote code execution. The exploit requires the site to use one of a handful of specific themes (twentyfifteen, twentyseventeen, twentysixteen, storefront, salient, or shapely).

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 4 mentions (2026-04-08); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-04-08: 4Mentions · 2026-04-11: 1Mentions · 2026-04-13: 1Mentions · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-11: 1Active Exploitation · 2026-04-11: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-08: 4Technical Details · 2026-04-11: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-23: 104-0804-1104-1304-23
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
Active Exploitation
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-084
Disclosure3Patch1
2026-04-111
Active Exploitation1
2026-04-131
Disclosure1
2026-04-231
Patch1
Full discourse7 posts
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    #WordPress Security Alert CVE-2026-3535: The DSGVO Google Web Fonts GDPR plugin for WordPress (<= 1.1) is vulnerable to unauthenticated arbitrary file upload. https://nvd.nist.gov/vuln/detail/CVE-2026-3535 CVSS score of 9.8 Critical. Successful exploitation can lead to PHP webshell upload and remote code execution on sites using certain themes, including Storefront. Update/remove the plugin immediately, check uploads for suspicious files, and scan for persistence. #WordPressSecurity #WooCommerce #CVE #WebsiteSecurity #RemoteCodeExecution #Malware #RCE

    Post summary

    An urgent alert warns that the DSGVO Google Web Fonts GDPR plugin for WordPress (≤1.1) allows unauthenticated file upload leading to RCE; users are instructed to update or remove the plugin and check for suspicious files.

    1000055
    40 followersView on X
  • SwissWPSecure@Swisswpsecure
    Active Exploitation

    🔴 CVE-2026-3535 — CVSS 9.8 — DSGVO Google Web Fonts GDPR Zero authentication. One POST request. Full webshell on your server. ➡ No patch exists ➡ Plugin appears abandoned ➡ Remove it now — replace with OMGF or Local Google Fonts This one is live and exploitable today. Full post: https://swisswpsecure.com/%f0%9f%9a%a8-wordpress-weekly-threat-report-april-6-11-2026-a-critical-zero-day-17-new-cves-and-wordpress-7-0-delayed/

    Post summary

    CVE-2026-3535 is an actively exploited vulnerability that allows a full webshell via a single POST request, with no patch available and no workaround offered.

    0001050
    1 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-3535 — CVSS 9.8/10 ██████████ The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/zjKGD4fEtM

    Post summary

    The tweet discloses CVE‑2026‑3535, a critical arbitrary file upload flaw in the DSGVO Google Web Fonts GDPR plugin for WordPress, and urges users to apply the available patch immediately.

    1000046
    16 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3535 The DSGVO Google Web Fonts GDPR plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the `DSGVOGWPdownloadGoogleFonts()` f… https://www.cve.org/CVERecord?id=CVE-2026-3535

    Post summary

    CVE-2026-3535 reveals an arbitrary file upload flaw in the DSGVO Google Web Fonts GDPR WordPress plugin due to missing file type validation, with no mention of PoC, exploit code, or patch.

    00000129
    57.1K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-3535、CVSS 9.8 (Critical) DSGVO Google Web Fonts GDPR &lt;= 1.1 - Unauthenticated Arbitrary File Upload via 'fonturl' Parameter https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dsgvo-google-web-fonts-gdpr/dsgvo-google-web-fonts-gdpr-11-unauthenticated-arbitrary-file-upload-via-fonturl-parameter

    Post summary

    A newly disclosed CVE (CVE-2026-3535) with a CVSS 9.8 score for an unauthenticated arbitrary file upload in the DSGVO Google Web Fonts plugin, as detailed on Wordfence’s threat‑intel page.

    00000658
    6.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3535: CRITICAL] Vulnerability in DSGVO Google Web Fonts GDPR plugin for WordPress allows unauthenticated attackers to upload malicious files, potentially leading to remote code execution.#cve,CVE-2026-3535,#cybersecurity https://cvefind.com/CVE-2026-3535

    Post summary

    The post announces CVE‑2026‑3535, detailing that the DSGVO Google Web Fonts GDPR plugin for WordPress allows unauthenticated users to upload malicious files that could result in remote code execution.

    0000059
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-3535: DSGVO Google Web Fonts GDPR &lt;= 1.... Zero-auth RCE via CSS URL poisoning - attackers can chain fonturl parameter abuse with theme detection to drop webshells... https://zerodaysignal.com/vulnerability/CVE-2026-3535 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-3535, a zero‑auth remote code execution flaw in Google Web Fonts via CSS URL poisoning that can drop web shells, referencing a detailed vulnerability report.

    0000061
    204 followersView on X

Explore more