Stored XSS in OMGF WordPress Plugin
The OMGF WordPress plugin is vulnerable to stored Cross-Site Scripting via the 's' parameter in comments-atom feeds, allowing unauthenticated script injection in environments where web servers permit MIME-sniffing.
CVE search metadata
CVE search record: CVE-2026-89417. Severity: high. CVSS: 7.2. KEV: no. Product: OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. (<= 6.3.10). Brief: Stored XSS in OMGF WordPress Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-omgf-xss/
The OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within the comments-atom feed. The vulnerability, tracked as CVE-2026-89417, affects all versions up to and including 6.3.10. An unauthenticated attacker can inject arbitrary web scripts into the search parameter 's'. When a user navigates to the resulting injected page, the script executes in the context of the user's browser session. The exploit's success depends on the underlying web server configuration; specifically, if the server serves the generated .tmp files without explicit 'Content-Type' or 'X-Content-Type-Options' headers, MIME-sniffing browsers - such as those based on Chromium - will execute the injected payload. This configuration deficiency is common in default Apache and nginx/php-fpm deployments, posing a significant risk for WordPress sites utilizing this plugin.
Attack Chain
- The attacker identifies a target WordPress site using the vulnerable OMGF plugin version 6.3.10 or lower.
- The attacker crafts a malicious HTTP GET request targeting the comments-atom feed.
- The attacker injects a JavaScript payload into the 's' search parameter within the request.
- The plugin fails to sanitize the input and stores the malicious script in a .tmp file.
- The web server serves the .tmp file to a victim user's browser.
- The web server omits 'Content-Type' or 'X-Content-Type-Options' headers in the response.
- The browser performs MIME-sniffing and interprets the stored script as executable content.
- The malicious script executes in the victim's session, potentially leading to session hijacking or credential theft.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's browser session. This can lead to unauthorized actions performed on behalf of authenticated users, session token theft, or redirecting users to malicious websites. The impact is elevated on sites where administrators frequently access affected feeds.
Recommendation
- Update the OMGF plugin to the latest version beyond 6.3.10 immediately upon release of a vendor patch.
- Implement strict Content-Security-Policy (CSP) headers on the web server to mitigate the impact of XSS by restricting the sources of executable scripts.
- Configure web servers (Apache or nginx/php-fpm) to explicitly send the 'X-Content-Type-Options: nosniff' header to prevent browser MIME-sniffing.
- Review web server logs for requests containing script-like characters or tags in the 's' query parameter.
Immediate actions
Patch OMGF plugin to a version > 6.3.10
Mitigations
Configure web server to set X-Content-Type-Options: nosniff
CVE-2026-89417