Open Graph

Open Graph has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.

The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).

The one issue recorded for Open Graph has a vendor fix available, so running the current release closes it.

All of these findings were reported by Krzysztof Zając. Open Graph is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
5.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Open Graph vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.3CVE-2024-5615

Open Graph <= 1.11.2 - Unauthenticated Sensitive Information Exposure

Read the full analysis

Vulnerability Records

1 records
Open Graph banner
Latestv2.0.2
4.3(13)
86/100
Last Updated
2026-08-21 (23d ago)
Active Installs
10,000+
Downloads
225,078
Requires WP
2.3+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2010-04-24 (17y ago)

The Open Graph protocol enables any web page to become a rich object in a social graph. Most notably, this allows for these pages to be used with Facebook’s Like Button and Graph API as well as within Twitter posts. The Open Graph plugin inserts the Open Graph metadata into WordPress posts and pages, and provides a simple extension mechanism for other plugins and themes to override this data, or to provide additional Open Graph data. This plugin does not directly add social plugins like the Facebook Like Button to your pages (though they’re pretty simple to add). It will however make your pages look great when shared using those kinds of tools.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C