Optiontree Project
optiontree_project
5 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Optiontree Project 1Optiontree Jun 17, 2026 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled. |
1Optiontree Project 1Optiontree Jun 17, 2026 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled. |
1Optiontree Project 1Optiontree Jun 17, 2026 Aug 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce. |
1Optiontree Project 1Optiontree Nov 21, 2024 Aug 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request. |
1Optiontree Project 1Optiontree Nov 21, 2024 Aug 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg. |