CyberzSOC

Publication detail
← Back to advisories & guidance

2024-001: Vulnerability in Wordpress Google Fonts Plugin ↗ source

January 8, 2024 CERT-EU Advisory

Summary

On January 2, 2024, an unauthenticated Stored Cross-Site Scripting (XSS) and directory deletion vulnerability has been discovered in the “OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. This vulnerability, identified as CVE-2023-6600 (CVSS score of 8.6)[1], may allow unauthenticated attackers to update the plugin’s settings and inject malicious scripts into affected sites [2]. This vulnerability could affect sites that have the OMGF plugin installed and configured, which is estimated to be over 300,000 sites [3]. The OMGF plugin vulnerability occurs due to a missing capability check on the update_settings() function hooked via admin_init . This allows unauthenticated attackers to modify the plugin’s settings, leading to Stored Cross-Site Scripting and directory deletion. “OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.” plugin version 5.7.9 and below. 5.7.10 as it contains the necessary fixes.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-6600 8.6 High daanvandenbergh OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.