CVE-2026-57700: WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files.
This issue affects OMGF Pro: from n/a through 5.2.6.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress OMGF Pro Pluginto a version that resolves this vulnerability.Fixed in 5.2.7 - Compensating control
Until the OMGF Pro plugin is updated, restrict access to the WordPress upload endpoint and block uploads of potentially dangerous file types at the web server/WAF.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57700?
The severity of CVE-2026-57700 is rated as critical with a score of 10.
How do I fix CVE-2026-57700?
To fix CVE-2026-57700, update the OMGF Pro plugin to version 5.2.7 or later.
What does CVE-2026-57700 affect?
CVE-2026-57700 affects the Daan.Dev OMGF Pro plugin versions up to and including 5.2.6.
What type of vulnerability is CVE-2026-57700?
CVE-2026-57700 is an Arbitrary File Upload vulnerability allowing the upload of malicious files.
Can CVE-2026-57700 lead to a security breach?
Yes, CVE-2026-57700 can potentially lead to a security breach by allowing attackers to upload and execute malicious files.