Opal Service
Opal Service has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Opal Service has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Muhammad Yudha - DJ. Opal Service is installed on roughly 900 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.0.27.
CVE-2025-62913Opal Service <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Opal Service
Author
wpopal
Opal Service is a flexible WordPress plugin that lets you display your company’s services in a variety of ways: as single pages, and even as embedded content blocks on the homepage of your website with the help of custom shortcodes. Features Detailed guide to install and customize: documentation Benefits For Users With Powerful Functions Of Potential Websites Completely integrated with Elementor page builder! Completely integrated with WPBakery Page Builder ! Completely integrated with Kingcomposer page builder! 100% responsive and mobile ready Easily Integrated to any WordPress websites. Quickly Set up, Publish & Update Friendly-user and Easy Customization Configuration The plugin is highly customizable, so you can apply it to any WordPress theme. In the settings section of the plugin you can do the following: Setting >> Display Setting – Can change the ‘Slug’ of Service and Service category; – Select page view layour for Service pages; – Select image sizes for Service pages; – Set a columns for to Service pages; – Set the number of services displayed on Service pages; – Choose display Thumnail, Category, Description, View Detail, Number for to Service pages;
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C