Sceawere

Vulnerability Detail

CVE-2026-91828UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OMGF Unauthenticated Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
17h ago
Vendor
Unknown
Product
OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy.
Attack Type
CWE-400 Uncontrolled Resource Consumption
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-02T06:16:42.857Z",
  "pubdate": "2026-10-02T06:16:42.857Z",
  "executiveSummary": "The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts WordPress plugin contains a vulnerability in versions prior to 6.3.11 that permits unauthenticated attackers to initiate a resource-exhaustion attack.\nThe issue stems from a lack of proper authentication and nonce verification on a specific administrative action, allowing external actors to trigger a slow server-side loopback request.\nBy repeatedly invoking this action, an attacker can consume the server's PHP worker pool, effectively rendering the website unavailable to legitimate users.\nThis vulnerability is classified as a Denial of Service (DoS) condition.\nIt is categorized by the absence of authorization checks on functionality that facilitates server-side request amplification, enabling an unauthenticated remote attacker to disrupt system availability without requiring elevated privileges.\nThe risk is significant due to the trivial nature of the exploit, which can be executed remotely over the network with minimal technical barrier, directly threatening site uptime and business continuity.",
  "technicalDetails": "The vulnerability resides within the OMGF plugin's request handling logic, specifically in an action responsible for initiating server-side loopback requests. The root cause is a failure to enforce authentication or cryptographically verify requests via nonces, rendering the sensitive endpoint publically accessible.\nThe mechanism of exploitation involves an unauthenticated attacker sending crafted HTTP requests to the vulnerable action endpoint. Because the plugin does not validate the identity of the requester, it processes these requests by triggering a loopback connection back to the hosting server.\nEach request initiates a computationally intensive or intentionally slow operation, such as the processing or synchronization of Google Fonts assets. By orchestrating a high volume of concurrent requests, the attacker induces resource contention within the web server's PHP-FPM pool.\nWhen the concurrent loopback requests exhaust the maximum number of available PHP workers, the server becomes unable to handle new incoming requests. This results in a persistent Denial of Service state, where legitimate traffic is queued or dropped, causing the site to become unresponsive.\nThe attack flow follows these steps: 1) The attacker identifies the exposed plugin action endpoint. 2) The attacker submits multiple parallel requests to this endpoint, requiring no authentication or valid session tokens. 3) The plugin executes the underlying server-side loopback request for each invocation. 4) The server enters a state of resource starvation as the PHP worker pool reaches its capacity limit. 5) Subsequent requests from site visitors are blocked, resulting in a system-wide outage.\nThis vulnerability affects all versions of OMGF before 6.3.11. The lack of network segmentation or rate limiting on this action makes it highly susceptible to exploitation by any remote host. The impact is strictly focused on availability, as the attack does not require direct access to sensitive data, though it effectively creates a total service disruption until the server processes are terminated or the load subsides."
}
CVE-2026-91828: OMGF Unauthenticated Denial of Service (HIGH Severity, CVSS: 7.5) | Sceawere