VendorsOptionTree Projectoptiontreeany version
Vulnerabilities

OptionTree Project OptionTree any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2019-15319
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
Published 2019-08-22 · Modified
9.8EPSS 0.021
CVE-2019-15320
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
Published 2019-08-22 · Modified
9.8EPSS 0.021
CVE-2019-15321
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
Published 2019-08-22 · Modified
9.8EPSS 0.021
CVE-2015-9320
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
Published 2019-08-20 · Modified
6.1EPSS 0.009
CVE-2016-10895
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
Published 2019-08-20 · Modified
6.1EPSS 0.009