OMGF Pro <= 5.2.7 - Unauthenticated Arbitrary File Download
high
The OMGF Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.2.7. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- CVSS:
- 7.5
- Affected:
- up to 5.2.7
- Fixed in:
- 5.2.8
- Disclosed:
- Aug 13, 2026
CVE-2026-61980 on NVD →
OMGF Pro <= 5.2.6 - Unauthenticated Arbitrary File Upload via @import URL Reflection
critical
The OMGF Pro plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 5.2.6. This is due to the ExternalStylesheets::optimize() method extracting attacker-controlled @import URLs from the rendered HTML, fetching their contents via wp_remote_get(), and writing those conte...
- CVSS:
- 9.8
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.7
- Disclosed:
- Jun 25, 2026
CVE-2026-57700 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database