Impact
The vulnerability is an unauthenticated arbitrary file download in the WordPress OMGF Pro plugin versions up to 5.2.7. An attacker can request any file on the server by manipulating the download parameter, allowing read of sensitive files. This flaw is a path traversal (CWE-22) that can compromise the confidentiality of site data.
Affected Systems
WordPress sites running the OMGF Pro plugin from Daan.dev, including all releases up to and including 5.2.7, are affected. The plugin is used to host Google Fonts; sites using these versions are susceptible.
Risk and Exploitability
The CVSS score of 7.5 highlights a high severity level. No EPSS rating is available, but the lack of authentication requirement indicates that the flaw can be exercised by anyone with network access. The vulnerability remains unlisted in the CISA KEV catalog, but the potential for data exposure means it should be treated with a high priority. Attackers could trigger unauthorized file reads simply by issuing a crafted HTTP request to the plugin’s download endpoint.
OpenCVE Enrichment