Skip to main content
Vulnerability Database/CVE-2026-89417

CVE-2026-89417: OMGF WordPress Plugin XSS Vulnerability

CVE-2026-89417 is a stored XSS flaw in the OMGF WordPress plugin that lets unauthenticated attackers inject malicious scripts through search parameters. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-89417 Overview

CVE-2026-89417 is a stored Cross-Site Scripting (XSS) vulnerability in the OMGF | GDPR/DSGVO Compliant, Faster Google Fonts WordPress plugin. All versions up to and including 6.3.10 are affected. The flaw originates in the plugin's handling of the s search parameter via the comments-atom feed. Insufficient input sanitization and output escaping allow unauthenticated attackers to inject arbitrary JavaScript that executes in visitors' browsers. The vulnerability is tracked under [CWE-79]: Improper Neutralization of Input During Web Page Generation.

Critical Impact

Unauthenticated attackers can inject persistent JavaScript that executes against any site visitor when the server serves the retained .tmp artifact without a Content-Type or X-Content-Type-Options header.

Affected Products

  • OMGF | GDPR/DSGVO Compliant, Faster Google Fonts plugin for WordPress — all versions through 6.3.10
  • Apache deployments serving plugin-generated .tmp files without X-Content-Type-Options: nosniff
  • nginx/php-fpm deployments without MIME-sniffing protections configured

Discovery Timeline

  • 2026-10-07 - CVE CVE-2026-89417 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-89417

Vulnerability Analysis

The OMGF plugin optimizes Google Fonts delivery by downloading and locally hosting font files. During processing, the plugin generates temporary .tmp files that are retained on the filesystem. The flaw lies in how the plugin processes the s search query parameter when it is reflected through the comments-atom feed. User-supplied input flows into generated output without proper sanitization or contextual escaping, enabling attackers to persist malicious script payloads.

Exploitation depends on a secondary condition at the web server tier. When Apache or nginx/php-fpm serves the retained .tmp artifact without a Content-Type header and without X-Content-Type-Options: nosniff, MIME-sniffing browsers such as Chromium interpret the file as HTML. The injected script then executes in the context of the hosting origin. This is a scope-changing issue, impacting users beyond the vulnerable component.

Root Cause

The root cause is missing input sanitization and output escaping on the s parameter as processed through the comments-atom feed pathway. Related plugin logic in src/Download.php, src/Frontend/Process.php, and src/Optimize.php writes untrusted content to persistent .tmp files without enforcing a safe response content type. Readers can review the pre-patch sources: Download.php L78, Process.php L411, and Optimize.php L159.

Attack Vector

An unauthenticated remote attacker crafts a request containing a script payload in the s query parameter aimed at the comments-atom feed endpoint. The payload is written into a cached .tmp artifact. When any site visitor subsequently requests the URL that serves the artifact, the browser MIME-sniffs it as HTML and executes the injected JavaScript. See the Wordfence advisory for detailed analysis.

See the Wordfence advisory and WordPress trac references for sanitized
technical details. No verified proof-of-concept code is published here.

Detection Methods for CVE-2026-89417

Indicators of Compromise

  • Unexpected .tmp files in the OMGF plugin cache directory containing <script> tags or event handlers such as onerror= or onload=
  • HTTP access log entries targeting /comments/feed/ or /?feed=comments-atom with suspicious s= parameters containing encoded HTML entities
  • Responses from .tmp artifacts missing Content-Type and X-Content-Type-Options headers
  • Browser console errors or Content Security Policy violations referencing OMGF cache paths

Detection Strategies

  • Inspect web server access logs for requests to the comments-atom feed carrying s parameter payloads with HTML or JavaScript syntax
  • Scan the plugin's cache directory for .tmp files containing script-like content
  • Review HTTP response headers served from plugin cache paths for missing X-Content-Type-Options: nosniff
  • Monitor for anomalous outbound requests from site visitors indicating client-side script execution

Monitoring Recommendations

  • Enable Web Application Firewall logging for query parameters on feed endpoints and alert on reflected markup
  • Baseline the contents and headers of the OMGF cache directory and alert on new .tmp files containing HTML elements
  • Track installed plugin versions across WordPress fleets and flag any instance of OMGF at or below 6.3.10

How to Mitigate CVE-2026-89417

Immediate Actions Required

  • Update the OMGF plugin to version 6.3.11 or later on every WordPress instance
  • Purge the OMGF cache directory to remove any poisoned .tmp artifacts
  • Add X-Content-Type-Options: nosniff to all responses served by Apache or nginx
  • Review recent access logs for exploitation attempts targeting the s parameter on comment feeds

Patch Information

The maintainers resolved the vulnerability in version 6.3.11. The code fix is documented in WordPress Changeset 3707539, with a full diff available via the changeset comparison. Administrators should upgrade through the WordPress plugin manager or via WP-CLI.

Workarounds

  • Deactivate and remove the OMGF plugin until the upgrade can be applied
  • Enforce X-Content-Type-Options: nosniff globally at the web server or reverse proxy layer
  • Deploy a WAF rule blocking HTML or script syntax in the s parameter on comments-atom requests
  • Restrict direct access to plugin cache directories through server configuration
bash
# Apache: add nosniff globally
Header always set X-Content-Type-Options "nosniff"

# nginx: add nosniff globally
add_header X-Content-Type-Options "nosniff" always;

# WP-CLI upgrade command
wp plugin update host-webfonts-local --version=6.3.11

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.