OptionTree <= 2.7.3 - Authenticated (Editor+) PHP Object Injection
medium
The OptionTree plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.7.3. This is due to deserialization of untrusted input. This makes it possible for authenticated attackers, with editor-level access and above, to inject a PHP Object. No known POP chain is present in the v...
- CVSS:
- 6.6
- Affected:
- up to 2.7.3
- Fix:
- No patched version reported
- Disclosed:
- Aug 18, 2026
CVE-2026-66620 on NVD →
Option Tree <= 2.5.5 - Cross-Site Scripting
medium
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
- CVSS:
- 6.1
- Affected:
- up to 2.5.5
- Fixed in:
- 2.6
- Disclosed:
- Aug 16, 2019
CVE-2016-10895 on NVD →
Option Tree <= 2.7.2 - Object Injection Bypass
high
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
- CVSS:
- 8.1
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.3
- Disclosed:
- May 19, 2019
CVE-2019-15320 on NVD →
Option Tree <= 2.7.2 - Object Injection Bypass
high
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
- CVSS:
- 8.1
- Affected:
- up to 2.7.2
- Fixed in:
- 2.7.3
- Disclosed:
- May 19, 2019
CVE-2019-15321 on NVD →
Option Tree <= 2.6.0 - PHP Object Injection
high
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
- CVSS:
- 8.1
- Affected:
- up to 2.6.0
- Fixed in:
- 2.7.0
- Disclosed:
- Apr 16, 2019
CVE-2019-15319 on NVD →
Option Tree <= 2.5.3 - Cross-Site Scripting
medium
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.
- CVSS:
- 6.1
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Apr 22, 2015
CVE-2015-9320 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database