CVE-2026-91828
OMGF < 6.3.11 - Unauthenticated DoS via do_optimize
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.
| Vendor | unknown |
| Product | omgf | gdpr/dsgvo compliant, faster google fonts. easy. |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown omgf | gdpr/dsgvo compliant, faster google fonts. easy.
Be the first to know when new unknown vulnerabilities affecting unknown omgf | gdpr/dsgvo compliant, faster google fonts. easy. are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
0 < 6.3.11
References
Credits
รngel Santana WPScan