Opensea
Opensea has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2023; 2 are fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 6.0, and the most serious one scores 6.3 out of 10. 2022 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Missing Authorization.
2 of the records (67%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2023.
2 independent researchers contributed these findings, one record each. Opensea is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.1.12.
CVE-2023-33999Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
Read the full analysisVulnerability Records

Opensea
Author
Alex Moss
The Opensea WordPress plugin allows you to embed any single NFT quickly and easily anywhere within your website with a simple shortcode. Simply install the plugin and follow the instructions on the Settings page. Opensea WordPress NFT plugin Plugin homepage. NFT Marketing by FireCask. External Dependencies It is worth noting that this plugin uses an external script to load the NFT embed capability. This script will not collect any data nor does it require any need to connect to any third party to enable the script itself. This is the script offered by Opensea and hosted via the unpkg.com CDN.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C