Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files.
This issue affects OMGF Pro: from n/a through 5.2.6.
CVE-2026-57700
Unrestricted File Upload Vulnerability in http://Daan.Dev OMGF Pro Through 5.2.6
https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-57700
Post summary
CVE-2026-57700 is an unrestricted file upload vulnerability affecting Daan.Dev OMGF Pro through version 5.2.6, with no PoC, exploit, active exploitation, or patch information provided.
🚨 CRITICAL - Unrestricted Dangerous File Upload in OMGF Pro (CVE-2026-57700)
CVE-2026-57700 is an unrestricted file upload flaw in the OMGF Pro (by http://Daan.Dev) plugin, allowing attackers to upload files with dangerous types to the WordPress environment. The root cause is improper input validation and insufficient server-side enforcement of allowed file types/paths during the upload handling flow. An attacker can exploit this by sending a crafted upload request to the vulnerable component and placing a malicious payload (e.g., PHP/webshell) on the server, depending on how the endpoint is exposed and what privileges are required in the target configuration. If successfully exploited, this can lead to full site compromise including remote code execution, persistent backdoors, data theft, and complete takeover of the underlying hosting account.
👉 Affected: OMGF Pro <= 5.2.6 | Upgrade to No fix yet - treat as suspicious
Post summary
The post announces a critical unrestricted file upload vulnerability (CVE‑2026‑57700) in OMGF Pro that could allow attackers to upload malicious PHP/webshell content and potentially achieve remote code execution, with no patch available yet.
🚨 CVE-2026-57700: OMGF Pro WordPress plugin <=5.2.6 has an unauthenticated arbitrary file upload flaw. CVSS 10 — no auth, full RCE potential. Update past 5.2.6 now. #WordPress#infosec https://secalerts.co/vulnerability/CVE-2026-57700?utm_campaign=x https://t.co/wWqBgbs4ya
Post summary
The tweet announces a new CVE with high severity and advises updating the affected plugin.