WordPress Plugin Vulnerabilities

OMGF < 6.3.11 - Unauthenticated DoS via do_optimize

Description

The plugin does not require authentication or a valid nonce on an action that issues a slow server-side loopback request, allowing unauthenticated attackers to exhaust the site's PHP worker pool and make the entire site unavailable.

Proof of Concept

Affects Plugins

Fixed in 6.3.11

References

Miscellaneous

Original Researcher
Ángel Santana
Submitter
Ángel Santana
Verified
Yes

Timeline

Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-29 (about 2 days ago)
Last Updated
2026-09-29 (about 2 days ago)

Other