OwnerRez

OwnerRez has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.0, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Missing Authorization.

Every one of the 3 issues recorded for OwnerRez has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. OwnerRez is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.0/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all OwnerRez vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-28957

OwnerRez <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

3 records
Plugin Profile
Latestv1.3.0
0.0(0)
0/100
Last Updated
2026-08-24 (20d ago)
Active Installs
700+
Downloads
14,331
Requires WP
5.4+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2020-12-14 (6y ago)

OwnerRez API WordPress Plugin The official WordPress plugin for the OwnerRez API. View the readme for more information on using this plugin. This plugin provides interconnectivity between your OwnerRez account and your WordPress website. This plugin will communicate with the OwnerRez API. The OwnerRez terms of service and privacy policy govern our usage of data collected through this plugin. Terms of Service Privacy Policy Please submit questions or problems to help@ownerrez.com

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C