CVE-2026-66620: WordPress OptionTree plugin <= 2.7.3 - PHP Object Injection vulnerability
Published Aug 18, 2026
·Updated
Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
Affected Software
1 affected component
WordPress OptionTree<=2.7.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress OptionTreeto a version that resolves this vulnerability.Fixed in 2.7.3
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Exploitation requires editor-level privileges, despite the network attack vector. Sites should focus triage on accounts that can access editor functionality in WordPress.
2
Which OptionTree versions are affected, and is the default configuration known to be vulnerable?
OptionTree versions up to and including 2.7.3 are identified as affected. The provided information does not state whether the vulnerable functionality is enabled in a default configuration.