WPHizmet

Eklenti güvenlik geçmişi

OMGF güvenlik açıkları

ABD Ulusal Güvenlik Açığı Veritabanı’nda (NVD) OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. eklentisi için 4 açık kaydı bulunuyor; en yenisi 2 Ekim 2026 tarihli. Bunların 3 tanesi kritik veya yüksek önemde, 2 tanesi oturum açmadan istismar edilebiliyor. Güncel sürüm 6.3.12.

Toplam kayıt
4
Kritik veya yüksek
3
Oturumsuz istismar
2
Son kayıt
2 Ekim 2026

Bilinen açık kayıtları

En yeniden eskiye. Her kaydın özgün metni NVD’de.

  • CVE-2026-91828Yüksek · 7,52 Ekim 2026

    hizmet dışı bırakma (DoS)

    Etkilenen sürümler: 6.3.11 öncesi · Oturum açmadan istismar edilebilir

    The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.

    Türkçe kayıt ve ne yapmalı
  • CVE-2023-6600Orta · 5,43 Ocak 2024

    depolanmış siteler arası betik çalıştırma (XSS)

    Etkilenen sürümler: 5.7.9 ve öncesi

    The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is vulnerable to unauthorized modification of data and Stored Cross-Site Scripting due to a missing capability check on the update_settings() function hooked via admin_init in all versions up to, and including, 5.7.9. This makes it possible for unauthenticated attackers to update the plugin's settings which can be used to inject Cross-Site Scripting payloads and delete entire directories. PLease note there were several attempted patched, and we consider 5.7.10 to be the most sufficiently patched.

  • CVE-2021-24639Yüksek · 8,120 Eylül 2021

    siteler arası istek sahteciliği (CSRF)

    Etkilenen sürümler: 4.5.4 öncesi

    The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on the server.

  • CVE-2021-24638Kritik · 9,120 Eylül 2021

    dizin geçişi (path traversal)

    Etkilenen sürümler: 4.5.4 öncesi · Oturum açmadan istismar edilebilir

    The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS, or download fonts uploaded on Google Fonts website.

Kaynak: NVD (kamu malı veri) ve WordPress.org eklenti dizini. Kayıtlar eklentinin WordPress.org adresi veya tam adıyla eşleştirilir. Veri 7 Ekim 2026 itibarıyla.