Admin Options Pages

Admin Options Pages has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Admin Options Pages has a vendor fix available, so running the current release closes it.

All of these findings were reported by Dimas Maulana. Admin Options Pages is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Admin Options Pages vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2025-23905

Admin Options Pages <= 0.9.7 - Reflected Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Admin Options Pages banner
Latestv0.9.9

Admin Options Pages

Johannes van Poelgeest

Author

Johannes van Poelgeest

5.0(9)
100/100
Last Updated
2026-08-13 (1mo ago)
Active Installs
500+
Downloads
7,815
Requires WP
5.3+
Requires PHP
8.0+
Tested up to
WP 7.0.4
Created
2019-03-27 (8y ago)

Admin Options Pages is a beautifully designed WordPress plugin, which makes it incredibly easy to create options menus, pages and fields. If you’re a seasoned developer or just a beginner, Admin Options Pages tries to make it easy for everybody. In a nutshell, you can make your own settings pages and add options fields to it and that without writing one single line of code. Use the get_option() function (link) to do with your option value (Field name) what you want. Field Types Text Textarea Wysiwyg Editor Number Checkbox Radio Select Image Color Picker Documentation Visit docs.adminoptionspages.com for the documentation. Bug reports or tips and ideas Bug reports for AOP are welcomed in our issues repository on Github. Tips and ideas are also welcome.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C