Cross-Site Scripting Vulnerability in OMGF WordPress Plugin
CVE-2023-6600
8.6HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 January 2024
What is CVE-2023-6600?
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts plugin for WordPress has a vulnerability stemming from inadequate capability checks within its update_settings() function. This oversight allows unauthenticated attackers to modify the plugin's settings. Such modifications enable the injection of Cross-Site Scripting payloads, potentially leading to data theft and unauthorized access. Additionally, attackers can exploit this vulnerability to delete entire directories. Multiple attempts have been made to patch the issue, with version 5.7.10 regarded as the most secure.
Affected Version(s)
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. 0 <= 5.7.9