Arbitrary File Upload in Daan.Dev OMGF Pro Plugin
CVE-2026-57700

10CRITICAL

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-57700?

The OMGF Pro plugin by Daan.Dev is susceptible to an unrestricted file upload vulnerability, enabling attackers to upload files of dangerous types. This flaw allows the execution of malicious files on the server, which can potentially compromise the website’s integrity and security. Users of versions n/a through 5.2.6 should evaluate their security configurations and apply necessary updates to mitigate this risk.

Affected Version(s)

OMGF Pro <= 5.2.6

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NETZLICHT | Patchstack Bug Bounty Program
.