CVE · Critical

CVE-2019-15319 — OptionTree [option-tree] < 2.7.0 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-15319 OptionTree [option-tree] < 2.7.0 (closed) Deserialization of Untrusted Data Critical 9.8 < 2.7.0 2.7.0 2019-04-16

CVE-2019-15319

The OptionTree plugin for WordPress before version 2.7.0 contains an object injection vulnerability that can be exploited when a valid nonce is present. This flaw allows an attacker to inject malicious objects into the application, potentially leading to code execution or other harmful actions. The vulnerability has been resolved in version 2.7.0 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.