Ffw develops WordPress optimization plugins including OMGF and Optimize My Google Fonts, which present a web-application attack surface centered on path-traversal weaknesses, cross-site request forgery, and missing authorization controls. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ffw over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24638CRITICAL The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite | Sep 20, 2021 | 9.1 | 29 | NO | NO |
CVE-2021-24639HIGH The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users | Sep 20, 2021 | 8.1 | 26 | NO | NO |
CVE-2021-25021MEDIUM The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and | Jan 3, 2022 | 4.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ffw.
Media articles that mention a CVE ID that affects a product developed by Ffw — matched by CVE ID, not by vendor name.