CVE-2026-91828: OMGF < 6.3.11 - Unauthenticated DoS via do_optimize
Published Oct 2, 2026
·Updated
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. WordPress plugin before 6.3.11 does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.
Affected Software
1 affected component
OMGF OMGF WordPress plugin<6.3.11
Event History
Oct 2, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated remote attacker can trigger the affected action. No login or valid nonce is required.
2
What is required for exploitation?
An attacker needs to send requests that invoke the do_optimize action. The action causes a slow server-side loopback request, and repeated requests can exhaust available PHP workers.
3
What is the operational impact?
Exploitation can consume the site's PHP worker pool and make the entire WordPress site unavailable.
4
Which plugin versions are affected?
OMGF versions before 6.3.11 are affected.