Opensea

Opensea has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2023; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 6.3 out of 10. 2022 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Missing Authorization.

2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2023.

2 independent researchers contributed these findings, one record each. Opensea is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.1.12.

Strategic Overview

Avg CVSSMedium
6.0/ 10
Patch Coverage67%
Open

1

Fixed

2

Get automatic notifications for all Opensea vulnerabilities before they are exploited.

Most severe open issueCVSS 6.1CVE-2023-33999

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

Read the full analysis

Vulnerability Records

3 records
Opensea banner
Latestv1.1
2.4(5)
48/100
Last Updated
2022-11-23 (4y ago)
Active Installs
200+
Downloads
13,936
Requires WP
5.1+
Requires PHP
0+
Tested up to
WP 6.1.12
Created
2021-04-14 (6y ago)

The Opensea WordPress plugin allows you to embed any single NFT quickly and easily anywhere within your website with a simple shortcode. Simply install the plugin and follow the instructions on the Settings page. Opensea WordPress NFT plugin Plugin homepage. NFT Marketing by FireCask. External Dependencies It is worth noting that this plugin uses an external script to load the NFT embed capability. This script will not collect any data nor does it require any need to connect to any third party to enable the script itself. This is the script offered by Opensea and hosted via the unpkg.com CDN.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C