CVE-2026-57700Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-25); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-26: 1Patch / Workaround · 2026-06-25: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 106-2506-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-252
Disclosure2
2026-06-261
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-57700 Unrestricted File Upload Vulnerability in http://Daan.Dev OMGF Pro Through 5.2.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-57700

    Post summary

    CVE-2026-57700 is an unrestricted file upload vulnerability affecting Daan.Dev OMGF Pro through version 5.2.6, with no PoC, exploit, active exploitation, or patch information provided.

    02021132
    4.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unrestricted Dangerous File Upload in OMGF Pro (CVE-2026-57700) CVE-2026-57700 is an unrestricted file upload flaw in the OMGF Pro (by http://Daan.Dev) plugin, allowing attackers to upload files with dangerous types to the WordPress environment. The root cause is improper input validation and insufficient server-side enforcement of allowed file types/paths during the upload handling flow. An attacker can exploit this by sending a crafted upload request to the vulnerable component and placing a malicious payload (e.g., PHP/webshell) on the server, depending on how the endpoint is exposed and what privileges are required in the target configuration. If successfully exploited, this can lead to full site compromise including remote code execution, persistent backdoors, data theft, and complete takeover of the underlying hosting account. 👉 Affected: OMGF Pro <= 5.2.6 | Upgrade to No fix yet - treat as suspicious

    Post summary

    The post announces a critical unrestricted file upload vulnerability (CVE‑2026‑57700) in OMGF Pro that could allow attackers to upload malicious PHP/webshell content and potentially achieve remote code execution, with no patch available yet.

    0000082
    231 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🚨 CVE-2026-57700: OMGF Pro WordPress plugin &lt;=5.2.6 has an unauthenticated arbitrary file upload flaw. CVSS 10 — no auth, full RCE potential. Update past 5.2.6 now. #WordPress #infosec https://secalerts.co/vulnerability/CVE-2026-57700?utm_campaign=x https://t.co/wWqBgbs4ya

    Post summary

    The tweet announces a new CVE with high severity and advises updating the affected plugin.

    0000082
    846 followersView on X

Explore more