WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Oxygen safe?

WordPress SEO plugin with AI SEO metadata, schema, XML sitemap, redirections & Search Console. Privacy-first, white-label SEO. Now AI-ready.

What this plugin does

  • Slug: oxygen
  • Author: Benjamin Denis
  • 300000+ active installs
  • 96/100 rating (1239 reviews on wordpress.org)
  • 19958429 all-time downloads
  • On WordPress.org since 2016-08-22

ai seogoogle search consoleschemaseoxml sitemap

Maintenance status

  • Last updated: 2026-07-01 9:44am GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 7.4+

Known vulnerabilities

1 known CVE on file for Oxygen. Reported between 2023 and 2024.

CVE Vulnerability Type Severity Affected Fixed in Published Status
Oxygen [oxygen] <= 4.9 (unfixed) Improper Control of Generation of Code ('Code Injection') Critical 9.9 < 4.9 4.9 2024-04-03
CVE-2022-46841 Oxygen [oxygen] < 4.4 Cross-Site Request Forgery (CSRF) Medium 5.4 < 4.4 4.4 2023-07-20

Oxygen [oxygen] <= 4.9 (unfixed)

The vendor provides no patched version for validation. Minor changes to documentation were made. Snicco discovered and reported this Remote Code Execution (RCE) vulnerability in WordPress Oxygen Builder Plugin. This could allow a malicious actor to execute commands on the target website. This can be used to gain backdoor access to then take full control of the website. This vulnerability has not been known to be fixed yet. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

CVE-2022-46841

The Oxygen plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.