CVE · Medium

CVE-2016-10895 — OptionTree [option-tree] < 2.6.0 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2016-10895 OptionTree [option-tree] < 2.6.0 (closed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.6.0 2.6.0 2019-08-16

CVE-2016-10895

The OptionTree WordPress plugin versions before 2.6.0 contained an authenticated cross-site scripting vulnerability that allowed logged-in users to inject malicious scripts into the application.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.