Impact
Unrestricted upload of files with dangerous types is possible through the OMGF Pro plugin. An attacker who can blog to the upload endpoint can deposit malicious executables or scripts that the WordPress environment might run, leading to full compromise of the site’s confidentiality, integrity, or availability.
Affected Systems
WordPress OMGF Pro plugin, developed by Daan.dev, with versions up to and including 5.2.6. All earlier releases are also affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 10, indicating extremely high severity. Because the plugin accepts uploads via a web form, the attack vector is inferred to be remotely exploitable over HTTP. The EPSS score is not available, but the lack of KEV listing suggests it is not yet widely exploited in the wild, though a CVSS of 10 warrants urgent remediation.
OpenCVE Enrichment