OwnerRez
OwnerRez has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.0, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Cross-Site Scripting, Missing Authorization.
Every one of the 3 issues recorded for OwnerRez has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. OwnerRez is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-28957OwnerRez <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
OwnerRez
Author
OwnerRez
OwnerRez API WordPress Plugin The official WordPress plugin for the OwnerRez API. View the readme for more information on using this plugin. This plugin provides interconnectivity between your OwnerRez account and your WordPress website. This plugin will communicate with the OwnerRez API. The OwnerRez terms of service and privacy policy govern our usage of data collected through this plugin. Terms of Service Privacy Policy Please submit questions or problems to help@ownerrez.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C