CVE · Critical

CVE-2019-15321 — OptionTree [option-tree] < 2.7.3 (closed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-15321 OptionTree [option-tree] < 2.7.3 (closed) Deserialization of Untrusted Data Critical 9.8 < 2.7.3 2.7.3 2019-05-19

CVE-2019-15321

The OptionTree plugin for WordPress before version 2.7.3 contains an object injection vulnerability due to improper handling of serialized class data. This flaw allows attackers to exploit the deserialization of untrusted serialized objects. The vulnerability affects all installations running versions prior to 2.7.3 and is resolved in version 2.7.3 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.