Resources /
WordPress Plugins /
Oxygen
PLUGIN SECURITY
Is Oxygen safe?
WordPress SEO plugin with AI SEO metadata, schema, XML sitemap, redirections & Search Console. Privacy-first, white-label SEO. Now AI-ready.
What this plugin does
- Slug:
oxygen
- Author: Benjamin Denis
- 300000+ active installs
- 96/100 rating (1239 reviews on wordpress.org)
- 19958429 all-time downloads
- On WordPress.org since 2016-08-22
ai seogoogle search consoleschemaseoxml sitemap
Maintenance status
- Last updated: 2026-07-01 9:44am GMT
- Tested up to WordPress: 7.0.2
- Requires PHP: 7.4+
Known vulnerabilities
1 known CVE on file for Oxygen.
Reported between 2023 and 2024.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
—
|
Oxygen [oxygen] <= 4.9 (unfixed) |
Improper Control of Generation of Code ('Code Injection') |
Critical
9.9
|
< 4.9
|
4.9 |
2024-04-03 |
—
|
|
CVE-2022-46841
|
Oxygen [oxygen] < 4.4 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 4.4
|
4.4 |
2023-07-20 |
—
|
Oxygen [oxygen] <= 4.9 (unfixed)
The vendor provides no patched version for validation. Minor changes to documentation were made.
Snicco discovered and reported this Remote Code Execution (RCE) vulnerability in WordPress Oxygen Builder Plugin. This could allow a malicious actor to execute commands on the target website. This can be used to gain backdoor access to then take full control of the website. This vulnerability has not been known to be fixed yet.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Source:
Patchstack
CVE-2022-46841
The Oxygen plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
Wordfence
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.