plugin

Option Tree Vulnerabilities

6 known security issues reported for the Option Tree WordPress plugin. Most recent disclosed Aug 18, 2026.

3 high 3 medium

Running Option Tree on your site? Check whether your installed version is affected.

Scan your site free

OptionTree <= 2.7.3 - Authenticated (Editor+) PHP Object Injection

medium

The OptionTree plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.7.3. This is due to deserialization of untrusted input. This makes it possible for authenticated attackers, with editor-level access and above, to inject a PHP Object. No known POP chain is present in the v...

CVSS:
6.6
Affected:
up to 2.7.3
Fix:
No patched version reported
Disclosed:
Aug 18, 2026

CVE-2026-66620 on NVD →

Option Tree <= 2.5.5 - Cross-Site Scripting

medium

The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.

CVSS:
6.1
Affected:
up to 2.5.5
Fixed in:
2.6
Disclosed:
Aug 16, 2019

CVE-2016-10895 on NVD →

Option Tree <= 2.7.2 - Object Injection Bypass

high

The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.

CVSS:
8.1
Affected:
up to 2.7.2
Fixed in:
2.7.3
Disclosed:
May 19, 2019

CVE-2019-15320 on NVD →

Option Tree <= 2.7.2 - Object Injection Bypass

high

The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.

CVSS:
8.1
Affected:
up to 2.7.2
Fixed in:
2.7.3
Disclosed:
May 19, 2019

CVE-2019-15321 on NVD →

Option Tree <= 2.6.0 - PHP Object Injection

high

The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.

CVSS:
8.1
Affected:
up to 2.6.0
Fixed in:
2.7.0
Disclosed:
Apr 16, 2019

CVE-2019-15319 on NVD →

Option Tree <= 2.5.3 - Cross-Site Scripting

medium

The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.

CVSS:
6.1
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
Apr 22, 2015

CVE-2015-9320 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database