Cross-site Scripting Vulnerability in Fontsplugin by Disable and Remove Google Fonts
CVE-2026-95595
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 October 2026
What is CVE-2026-95595?
A Cross-site Scripting (XSS) vulnerability exists in the Disable and Remove Google Fonts plugin for WordPress, which allows attackers to inject malicious scripts into web pages. This flaw affects versions from n/a to 2.0.2, enabling the execution of arbitrary JavaScript in the context of a user's browser, potentially compromising sensitive information or hijacking user sessions.
Affected Version(s)
Disable and Remove Google Fonts | GDPR & DSGVO friendly <= 2.0.2