OpenInviter for WordPress
OpenInviter for WordPress has one disclosed vulnerability in the WordSec catalog, all reported in 2013; it remains unpatched as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Insertion Of Sensitive Information Into Log File, behind 1 of the records (100%).
The one issue recorded for OpenInviter for WordPress has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2013.
All of these findings were reported by Ryuzaki Lawlet. OpenInviter for WordPress is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 2.6.2.
OpenInviter for WordPress <= 1.7.0 - Sensitive Information Disclosure
Read the full analysisVulnerability Records
OpenInviter for WordPress
Import contacts from the Address Book from Yahoo!, GMail, AOL, Hotmail and other providers. The plugin also provides all the nice features of OpenInviter: auto-updates both local and remote debugging Supported services: AOL GMail Windows Live (Hotmail) Yahoo! Rediff Lycos Mail.com Mail.ru Rambler.ru Twitter MySpace Facebook Hi5 Orkut GMX.net Services coming soon: GMX.com Email.it Fastmail.fm Canada.com YouTube (and many others…) 🙂
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C