Cross-Site Scripting Vulnerability in OMGF WordPress Plugin
CVE-2023-6600

8.6HIGH

What is CVE-2023-6600?

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts plugin for WordPress has a vulnerability stemming from inadequate capability checks within its update_settings() function. This oversight allows unauthenticated attackers to modify the plugin's settings. Such modifications enable the injection of Cross-Site Scripting payloads, potentially leading to data theft and unauthorized access. Additionally, attackers can exploit this vulnerability to delete entire directories. Multiple attempts have been made to patch the issue, with version 5.7.10 regarded as the most secure.

Affected Version(s)

OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. 0 <= 5.7.9

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.