PatchSiren cyber security CVE debrief
CVE-2026-95595 Fontsplugin CVE debrief
A Cross Site Scripting (XSS) vulnerability exists in the WordPress plugin Disable and Remove Google Fonts | GDPR & DSGVO friendly versions up to 2.0.2. This issue allows for Reflected XSS attacks. The vulnerability is caused by improper neutralization of input during web page generation. Defenders should assess exposure and prioritize remediation to prevent potential XSS attacks. The plugin's vulnerability management and security teams should verify plugin versions and upgrade if necessary.
- Vendor
- Fontsplugin
- Product
- Disable and Remove Google Fonts | GDPR & DSGVO friendly
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for WordPress installations with the Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin should assess exposure and prioritize remediation. The plugin's vulnerability management and security teams should verify plugin versions and upgrade if necessary to prevent potential XSS attacks. Additionally, operators and platform administrators should review the vulnerability and implement necessary mitigations to prevent potentialX
Why it matters
CVE-2026-95595 is a Cross Site Scripting (XSS) vulnerability in the WordPress plugin Disable and Remove Google Fonts | GDPR & DSGVO friendly. Defenders should verify plugin versions and upgrade if necessary to prevent potential XSS attacks.
- Defenders need to verify if their WordPress installations are using a vulnerable version of the plugin.
- Successful exploitation could lead to XSS attacks, potentially allowing attackers to inject malicious scripts.
Technical summary
The Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin for WordPress has a Reflected Cross Site Scripting (XSS) vulnerability in versions up to 2.0.2. This vulnerability allows an attacker to inject malicious scripts into the plugin's web pages. The vulnerability is caused by improper neutralization of input during web page generation. Defenders should prioritize verifying the version of the plugin and upgrading to a patched version if necessary to prevent potential XSS attacks. The plugin's technical teams should review the vulnerability and implement necessary fixes.
Defensive priority
Defenders should prioritize verifying the version of the Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin and upgrading to a patched version if necessary.
Recommended defensive actions
- Verify the version of the Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin
- Upgrade to a patched version if necessary
- Monitor for potential XSS attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its existence in versions up to 2.0.2 of the plugin. The source item provides additional context on the vulnerability, including its impact on WordPress installations. Defenders should verify plugin versions and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-95595 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-95595
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-95595 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95595
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
WordPress Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin <= 2.0.2 - Cross Site S
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/95xxx/CVE-2026-95595.json
cve_program_cvelist_v5
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.