Quttera - eCommerce Security[verified]@MNovofastovskyPatch
An urgent alert warns that the DSGVO Google Web Fonts GDPR plugin for WordPress (≤1.1) allows unauthenticated file upload leading to RCE; users are instructed to update or remove the plugin and check for suspicious files.
SwissWPSecure[verified]@SwisswpsecureActive Exploitation
CVE-2026-3535 is an actively exploited vulnerability that allows a full webshell via a single POST request, with no patch available and no workaround offered.
Orizon[verified]@OrizonCyberPatch
The tweet discloses CVE‑2026‑3535, a critical arbitrary file upload flaw in the DSGVO Google Web Fonts GDPR plugin for WordPress, and urges users to apply the available patch immediately.
CVE@CVEnewDisclosure
CVE-2026-3535 reveals an arbitrary file upload flaw in the DSGVO Google Web Fonts GDPR WordPress plugin due to missing file type validation, with no mention of PoC, exploit code, or patch.
Autumn Good@autumn_good_35Disclosure
A newly disclosed CVE (CVE-2026-3535) with a CVSS 9.8 score for an unauthenticated arbitrary file upload in the DSGVO Google Web Fonts plugin, as detailed on Wordfence’s threat‑intel page.
CVEFind.com@CveFindComDisclosure
The post announces CVE‑2026‑3535, detailing that the DSGVO Google Web Fonts GDPR plugin for WordPress allows unauthenticated users to upload malicious files that could result in remote code execution.
0day Signal@0dayPublishingDisclosure
The post announces CVE-2026-3535, a zero‑auth remote code execution flaw in Google Web Fonts via CSS URL poisoning that can drop web shells, referencing a detailed vulnerability report.