PatchSiren

Fontsplugin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Fontsplugin CVE published 2026-10-07

CVE-2026-95595

A Cross Site Scripting (XSS) vulnerability exists in the WordPress plugin Disable and Remove Google Fonts | GDPR & DSGVO friendly versions up to 2.0.2. This issue allows for Reflected XSS attacks. The vulnerability is caused by improper neutralization of input during web page generation. Defenders should assess exposure and prioritize remediation to prevent potential XSS attacks. The plugin's vulnerabilit [truncated]