PLUGIN SECURITY
Is Option Tree safe?
Theme Options UI Builder for WordPress. A simple way to create & save Theme Options and Meta Boxes for free or premium themes.
What this plugin does
- Slug:
option-tree - Author: Derek Herman
- 50000+ active installs
- 94/100 rating (105 reviews on wordpress.org)
- 1320248 all-time downloads
- On WordPress.org since 2010-10-19
meta boxesoptionssettingstheme options
Maintenance status
- Latest known version: 2.7.3
- Last updated: 2019-05-19 5:05am GMT
- Tested up to WordPress: 5.2.26
- Requires PHP: 5.3.0+
- Max supported PHP (analyzed): 8.4
⚠ Option Tree hasn't been updated in over 2661 days. An unmaintained plugin doesn't receive new security fixes, which is itself a security risk even without a known CVE.
Known vulnerabilities
6 known CVEs on file for Option Tree. Reported between 2015 and 2019.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2016-10895 | OptionTree [option-tree] < 2.6.0 (closed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.6.0 | 2.6.0 | 2019-08-16 | ✓ fixed in latest |
| CVE-2026-66620 | OptionTree [option-tree] <= 2.7.3 (unfixed + closed) | Deserialization of Untrusted Data | High 7.2 | < 2.7.3 | 2.7.3 | 2019-08-16 | ✓ fixed in latest |
| CVE-2019-15320, CVE-2019-15321 | OptionTree [option-tree] < 2.7.3 (closed) | Deserialization of Untrusted Data | Critical 9.8 | < 2.7.3 | 2.7.3 | 2019-05-19 | ✓ fixed in latest |
| CVE-2019-15321 | OptionTree [option-tree] < 2.7.3 (closed) | Deserialization of Untrusted Data | Critical 9.8 | < 2.7.3 | 2.7.3 | 2019-05-19 | ✓ fixed in latest |
| CVE-2019-15319 | OptionTree [option-tree] < 2.7.0 (closed) | Deserialization of Untrusted Data | Critical 9.8 | < 2.7.0 | 2.7.0 | 2019-04-16 | ✓ fixed in latest |
| CVE-2015-9320 | OptionTree [option-tree] < 2.5.4 (closed) | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.5.4 | 2.5.4 | 2015-04-22 | ✓ fixed in latest |
How to fix it
Keep Option Tree updated — 2.7.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Redux Framework — 900000+ active installs — 88/100 (273) — max PHP 8.4
- CMB2 — 300000+ active installs — 100/100 (91) — max PHP 8.4
- ACF Options For Polylang — 20000+ active installs — 88/100 (17) — max PHP 8.4
- Options Framework — 10000+ active installs — 96/100 (27)
- AAA Option Optimizer — 9000+ active installs — 92/100 (25)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.