PLUGIN SECURITY

Is Option Tree safe?

Theme Options UI Builder for WordPress. A simple way to create & save Theme Options and Meta Boxes for free or premium themes.

What this plugin does

  • Slug: option-tree
  • Author: Derek Herman
  • 50000+ active installs
  • 94/100 rating (105 reviews on wordpress.org)
  • 1320248 all-time downloads
  • On WordPress.org since 2010-10-19

meta boxesoptionssettingstheme options

Maintenance status

  • Latest known version: 2.7.3
  • Last updated: 2019-05-19 5:05am GMT
  • Tested up to WordPress: 5.2.26
  • Requires PHP: 5.3.0+
  • Max supported PHP (analyzed): 8.4

⚠ Option Tree hasn't been updated in over 2661 days. An unmaintained plugin doesn't receive new security fixes, which is itself a security risk even without a known CVE.

Known vulnerabilities

6 known CVEs on file for Option Tree. Reported between 2015 and 2019.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2016-10895 OptionTree [option-tree] < 2.6.0 (closed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.6.0 2.6.0 2019-08-16 ✓ fixed in latest
CVE-2026-66620 OptionTree [option-tree] <= 2.7.3 (unfixed + closed) Deserialization of Untrusted Data High 7.2 < 2.7.3 2.7.3 2019-08-16 ✓ fixed in latest
CVE-2019-15320, CVE-2019-15321 OptionTree [option-tree] < 2.7.3 (closed) Deserialization of Untrusted Data Critical 9.8 < 2.7.3 2.7.3 2019-05-19 ✓ fixed in latest
CVE-2019-15321 OptionTree [option-tree] < 2.7.3 (closed) Deserialization of Untrusted Data Critical 9.8 < 2.7.3 2.7.3 2019-05-19 ✓ fixed in latest
CVE-2019-15319 OptionTree [option-tree] < 2.7.0 (closed) Deserialization of Untrusted Data Critical 9.8 < 2.7.0 2.7.0 2019-04-16 ✓ fixed in latest
CVE-2015-9320 OptionTree [option-tree] < 2.5.4 (closed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 2.5.4 2.5.4 2015-04-22 ✓ fixed in latest

How to fix it

Keep Option Tree updated — 2.7.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.