Open Graph
Open Graph has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).
The one issue recorded for Open Graph has a vendor fix available, so running the current release closes it.
All of these findings were reported by Krzysztof Zając. Open Graph is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-5615Open Graph <= 1.11.2 - Unauthenticated Sensitive Information Exposure
Read the full analysisVulnerability Records

Open Graph
Author
Will Norris
The Open Graph protocol enables any web page to become a rich object in a social graph. Most notably, this allows for these pages to be used with Facebook’s Like Button and Graph API as well as within Twitter posts. The Open Graph plugin inserts the Open Graph metadata into WordPress posts and pages, and provides a simple extension mechanism for other plugins and themes to override this data, or to provide additional Open Graph data. This plugin does not directly add social plugins like the Facebook Like Button to your pages (though they’re pretty simple to add). It will however make your pages look great when shared using those kinds of tools.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C