Admin Options Pages
Admin Options Pages has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Admin Options Pages has a vendor fix available, so running the current release closes it.
All of these findings were reported by Dimas Maulana. Admin Options Pages is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-23905Admin Options Pages <= 0.9.7 - Reflected Cross-Site Scripting
Read the full analysisVulnerability Records

Admin Options Pages
Author
Johannes van Poelgeest
Admin Options Pages is a beautifully designed WordPress plugin, which makes it incredibly easy to create options menus, pages and fields. If you’re a seasoned developer or just a beginner, Admin Options Pages tries to make it easy for everybody. In a nutshell, you can make your own settings pages and add options fields to it and that without writing one single line of code. Use the get_option() function (link) to do with your option value (Field name) what you want. Field Types Text Textarea Wysiwyg Editor Number Checkbox Radio Select Image Color Picker Documentation Visit docs.adminoptionspages.com for the documentation. Bug reports or tips and ideas Bug reports for AOP are welcomed in our issues repository on Github. Tips and ideas are also welcome.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C