The TK Google Fonts GDPR Compliant plugin for WordPress had an issue in versions up to and including 2.2.7 that allowed anyone to make changes to the plugin’s settings without needing any special permission. This was due to the lack of checks that the plugin had in place to verify if a user had the right to make changes, as well as the lack of a verification system that would check if someone was authorized to make changes.