OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy., CVE-2023-6600
- CVE, Research URL
- Published on
- Jan 03, 2024
- Research Description
- The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init in all versions up to, and including, 5.7.9. This makes it possible for unauthenticated attackers to update the plugin's settings which can be used to inject Cross-Site Scripting payloads and delete entire directories. PLease note there were several attempted patched, and we consider 5.7.10 to be the most sufficiently patched.
- Affected versions
-
max 5.7.10.
- Status
-
vulnerable