Impact
This vulnerability is present in versions of the OMGF WordPress plugin before 6.3.11. By sending a specially constructed HTTP request that calls the do_optimize action, an attacker can trigger a long server‑side loopback request. Because the action bypasses all authentication and nonce checks, anyone on the public internet can invoke it. The repetitive request loop consumes PHP worker processes until the pool is exhausted, resulting in a denial of service that can render the entire WordPress site unavailable.
Affected Systems
The affected product is the OMGF WordPress plugin, also marketed as GDPR/DSGVO Compliant, Faster Google Fonts. Easy. All installations running a version earlier than 6.3.11 are vulnerable; newer releases contain the fix.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, so there is no publicly known exploitation evidence. However, the lack of authentication requirements and the presence of a resource‑intensive operation make exploitation trivial for remote attackers; no special access or credentials are required. If an attacker succeeds, the site can be taken offline for extended periods, impacting availability and potentially disrupting business and revenue.
OpenCVE Enrichment