Google Fonts Plugin Puts Over 300,000 WordPress Sites At Risk From Online Attackers

We may receive a commission from our partners if you click on a link and purchase a product or service on their website. Learn more

headshot of Sam Jagger
Written By
Published on January 9, 2024
a graphic of security images and locks on a laptop
  • A Google Fonts plugin for WordPress, “OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy”, has been found to have a severe vulnerability.
  • The plugin, which has been downloaded over 300,000 times, can give hackers access to entire directories and upload malicious scripts.

A Google Fonts plugin for WordPress blogs was found to have a major vulnerability, resulting in over 300,000 accounts being made vulnerable to hackers.

The plugin, “OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy”, optimizes Google Fonts to reduce loading while also making it GDPR compliant, making it useful for EU customers who wish to use Google Fonts.

However, on January 2nd, 2024, Wordfence published a report that the plugin had failed what is known as a capability check, which checks whether the user has access to the plugin, including up to the admin level. As the Wordfence report states, “This

[now]

makes it possible for unauthenticated attackers to update the plugin’s settings which can be used to inject cross-site scripting payloads and delete entire directories”

Cross-site scripting is a type of cyber attack in which malicious code is uploaded to the website and its server. This script then allows hackers to attack the browsers of any visiting user, gaining access to their personal information. Cross-site scripting attacks are among the most common – and effective – cyber-attacks affecting average users, accounting for over 40% of all cyber attacks in 2019.

This is especially egregious when you consider the mundanity of the plugin since most WordPress blogs would be eager to download Google Fonts for the simple variety in content, yet had no idea that they could now be targeted by ruthless hackers.

As of January 3rd, the plugin has been patched thanks to update 5.7.10, but it is crucial to always be wary of potential plugin vulnerabilities, as we reported a similar story last year.

More Information:

Written By

headshot of Sam Jagger

Hi, I’m Sam:

Samuel Jagger is a Senior Writer at Website Builder Expert, specializing in AI integration and web design theory. He has created editorial content for the publication since 2022 and has covered topics ranging from website design, ecommerce, digital marketing, and more. He’s written articles for apps like UXPin on web design in the modern age, as well as answered over 100 user comments on the site. Sam has also created his own websites, such as this Strikingly demo you can view here. He also writes and stars in the official WBE TikToks, sharing helpful website tips and commenting on the latest in website design news.

Previously, Samuel worked as a Freelance Blog Writer for The MIZU Hub and as a Digital Content Creator for Europa Music Management, working with musical artists like Purple Disco Machine, David Penn, and Monolink. Samuel has a Master of Arts in Creative Writing and a Bachelor of Arts in Film Practices from Newcastle University, where he graduated with honors and distinction.

Samuel is passionate about writing, visual media, and the creative arts. He is always looking for new avenues to funnel his creativity and align his skills with projects that interest him. You can find him and keep up to date with what he’s up to on his LinkedIn.

More about

0 comments

Your email address will not be published. Required fields are marked *