Description
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files.

This issue affects OMGF Pro: from n/a through 5.2.6.
Published: 2026-06-25
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unrestricted upload of files with dangerous types is possible through the OMGF Pro plugin. An attacker who can blog to the upload endpoint can deposit malicious executables or scripts that the WordPress environment might run, leading to full compromise of the site’s confidentiality, integrity, or availability.

Affected Systems

WordPress OMGF Pro plugin, developed by Daan.dev, with versions up to and including 5.2.6. All earlier releases are also affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 10, indicating extremely high severity. Because the plugin accepts uploads via a web form, the attack vector is inferred to be remotely exploitable over HTTP. The EPSS score is not available, but the lack of KEV listing suggests it is not yet widely exploited in the wild, though a CVSS of 10 warrants urgent remediation.

Generated by OpenCVE AI on June 25, 2026 at 19:41 UTC.

Remediation

Vendor Solution

Update the WordPress OMGF Pro Plugin to the latest available version (at least 5.2.7).


OpenCVE Recommended Actions

  • Update the WordPress OMGF Pro plugin to version 5.2.7 or later.
  • If a patch cannot be applied immediately, block or restrict the plugin’s upload functionality and allow only safe file types.
  • Continuously monitor the site for unexpected file uploads or execution events, and audit logs for suspicious activity.

Generated by OpenCVE AI on June 25, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 25 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.
Title WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-25T17:29:31.795Z

Reserved: 2026-06-25T08:03:56.313Z

Link: CVE-2026-57700

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-25T19:45:16Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type