Eklenti güvenlik geçmişi
OMGF güvenlik açıkları
ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. eklentisi için 4 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 3 tanesi kritik veya yüksek önemde, 2 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 6.3.12.
- Toplam kayıt
- 4
- Kritik veya yüksek
- 3
- Oturumsuz istismar
- 2
- Son kayıt
- 2 Ekim 2026
Bilinen açık kayıtları
En yeniden eskiye. Her kaydın özgün metni NVD’de.
hizmet dışı bırakma (DoS)
Etkilenen sürümler: 6.3.11 öncesi · Oturum açmadan istismar edilebilir
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.
Türkçe kayıt ve ne yapmalıdepolanmış siteler arası betik çalıştırma (XSS)
Etkilenen sürümler: 5.7.9 ve öncesi
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init in all versions up to, and including, 5.7.9. This makes it possible for unauthenticated attackers to update the plugin's settings which can be used to inject Cross-Site Scripting payloads and delete entire directories. PLease note there were several attempted patched, and we consider 5.7.10 to be the most sufficiently patched.
siteler arası istek sahteciliği (CSRF)
Etkilenen sürümler: 4.5.4 öncesi
The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.
dizin geçişi (path traversal)
Etkilenen sürümler: 4.5.4 öncesi · Oturum açmadan istismar edilebilir
The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.
Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.