Loading product vulnerabilities…
Total
5
Critical
0
High
0
Medium
1
CISA KEV
0
The option-tree plugin before 2.7.3 for WordPress has Object Injection because serialized classes are mishandled.
The option-tree plugin before 2.7.3 for WordPress has Object Injection because the + character is mishandled.
The option-tree plugin before 2.7.0 for WordPress has Object Injection by leveraging a valid nonce.
The option-tree plugin before 2.6.0 for WordPress has XSS via an add_list_item or add_social_links AJAX request.
The option-tree plugin before 2.5.4 for WordPress has XSS related to add_query_arg.