CVE Database /
CVE-2019-15320
CVE · Critical
CVE-2019-15320 — OptionTree [option-tree] < 2.7.3 (closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-15320, CVE-2019-15321
|
OptionTree [option-tree] < 2.7.3 (closed) |
Deserialization of Untrusted Data |
Critical
9.8
|
< 2.7.3
|
2.7.3 |
2019-05-19 |
—
|
CVE-2019-15320, CVE-2019-15321
The OptionTree plugin for WordPress before version 2.7.3 contains an object injection vulnerability stemming from improper handling of the plus character. This flaw could allow attackers to manipulate serialized objects and potentially execute arbitrary code or compromise site security.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings