{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/omgf--gdpr/dsgvo-compliant-faster-google-fonts.-easy.--6.3.10/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:daanvandenbergh:omgf:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-89417"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. (\u003c= 6.3.10)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Daan van den Bergh"],"content_html":"\u003cp\u003eThe OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within the comments-atom feed. The vulnerability, tracked as CVE-2026-89417, affects all versions up to and including 6.3.10. An unauthenticated attacker can inject arbitrary web scripts into the search parameter 's'. When a user navigates to the resulting injected page, the script executes in the context of the user's browser session. The exploit's success depends on the underlying web server configuration; specifically, if the server serves the generated .tmp files without explicit 'Content-Type' or 'X-Content-Type-Options' headers, MIME-sniffing browsers - such as those based on Chromium - will execute the injected payload. This configuration deficiency is common in default Apache and nginx/php-fpm deployments, posing a significant risk for WordPress sites utilizing this plugin.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a target WordPress site using the vulnerable OMGF plugin version 6.3.10 or lower.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP GET request targeting the comments-atom feed.\u003c/li\u003e\n\u003cli\u003eThe attacker injects a JavaScript payload into the 's' search parameter within the request.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to sanitize the input and stores the malicious script in a .tmp file.\u003c/li\u003e\n\u003cli\u003eThe web server serves the .tmp file to a victim user's browser.\u003c/li\u003e\n\u003cli\u003eThe web server omits 'Content-Type' or 'X-Content-Type-Options' headers in the response.\u003c/li\u003e\n\u003cli\u003eThe browser performs MIME-sniffing and interprets the stored script as executable content.\u003c/li\u003e\n\u003cli\u003eThe malicious script executes in the victim's session, potentially leading to session hijacking or credential theft.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of a victim's browser session. This can lead to unauthorized actions performed on behalf of authenticated users, session token theft, or redirecting users to malicious websites. The impact is elevated on sites where administrators frequently access affected feeds.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the OMGF plugin to the latest version beyond 6.3.10 immediately upon release of a vendor patch.\u003c/li\u003e\n\u003cli\u003eImplement strict Content-Security-Policy (CSP) headers on the web server to mitigate the impact of XSS by restricting the sources of executable scripts.\u003c/li\u003e\n\u003cli\u003eConfigure web servers (Apache or nginx/php-fpm) to explicitly send the 'X-Content-Type-Options: nosniff' header to prevent browser MIME-sniffing.\u003c/li\u003e\n\u003cli\u003eReview web server logs for requests containing script-like characters or tags in the 's' query parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T10:36:27Z","date_published":"2026-10-07T10:36:27Z","id":"https://feed.craftedsignal.io/briefs/2026-10-omgf-xss/","summary":"The OMGF WordPress plugin is vulnerable to stored Cross-Site Scripting via the 's' parameter in comments-atom feeds, allowing unauthenticated script injection in environments where web servers permit MIME-sniffing.","title":"Stored XSS in OMGF WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-omgf-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - OMGF | GDPR/DSGVO Compliant, Faster Google Fonts. Easy. (\u003c= 6.3.10)","version":"https://jsonfeed.org/version/1.1"}