PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-95595 Fontsplugin CVE debrief

A Cross Site Scripting (XSS) vulnerability exists in the WordPress plugin Disable and Remove Google Fonts | GDPR & DSGVO friendly versions up to 2.0.2. This issue allows for Reflected XSS attacks. The vulnerability is caused by improper neutralization of input during web page generation. Defenders should assess exposure and prioritize remediation to prevent potential XSS attacks. The plugin's vulnerability management and security teams should verify plugin versions and upgrade if necessary.

Vendor
Fontsplugin
Product
Disable and Remove Google Fonts | GDPR & DSGVO friendly
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for WordPress installations with the Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin should assess exposure and prioritize remediation. The plugin's vulnerability management and security teams should verify plugin versions and upgrade if necessary to prevent potential XSS attacks. Additionally, operators and platform administrators should review the vulnerability and implement necessary mitigations to prevent potentialX

Why it matters

CVE-2026-95595 is a Cross Site Scripting (XSS) vulnerability in the WordPress plugin Disable and Remove Google Fonts | GDPR & DSGVO friendly. Defenders should verify plugin versions and upgrade if necessary to prevent potential XSS attacks.

  • Defenders need to verify if their WordPress installations are using a vulnerable version of the plugin.
  • Successful exploitation could lead to XSS attacks, potentially allowing attackers to inject malicious scripts.

Technical summary

The Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin for WordPress has a Reflected Cross Site Scripting (XSS) vulnerability in versions up to 2.0.2. This vulnerability allows an attacker to inject malicious scripts into the plugin's web pages. The vulnerability is caused by improper neutralization of input during web page generation. Defenders should prioritize verifying the version of the plugin and upgrading to a patched version if necessary to prevent potential XSS attacks. The plugin's technical teams should review the vulnerability and implement necessary fixes.

Defensive priority

Defenders should prioritize verifying the version of the Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin and upgrading to a patched version if necessary.

Recommended defensive actions

  • Verify the version of the Disable and Remove Google Fonts | GDPR & DSGVO friendly plugin
  • Upgrade to a patched version if necessary
  • Monitor for potential XSS attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its existence in versions up to 2.0.2 of the plugin. The source item provides additional context on the vulnerability, including its impact on WordPress installations. Defenders should verify plugin versions and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-95595 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-95595

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-95595 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-95595

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.