CVE-2026-57700

CRITICAL EXPLOITED

WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-57700 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

Scores

CVSS v3 10.0
EPSS 0.0036
EPSS Percentile 28.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-06-25
CWE
CWE-434
Status published
Products (1)
Daan.dev/OMGF Pro < 5.2.6
Published Jun 25, 2026
Tracked Since Jun 26, 2026