OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-91828

HIGH · CVSS 7.5 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The OMGF plugin for WordPress, prior to version 6.3.11, is vulnerable to unauthenticated attacks that can exploit a lack of authentication on a specific action, leading to a denial-of-service condition by exhausting the site's PHP worker pool. This vulnerability can render the entire site unavailable, making it critical for WordPress site administrators using this plugin to prioritize immediate updates to mitigate potential service disruptions.

CVE
CVE-2026-91828
Severity
HIGH
CVSS
7.5
EPSS
0.31%
WordPress

Original NVD Description

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.