OpenHook
OpenHook has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; 1 is fixed and 1 remains unpatched as of September 2026. Their average CVSS score is 7.1, and the most serious one scores 9.9 out of 10. Severity breakdown: 1 critical and 0 high.
The most common weakness is Code Injection, behind 1 of the records (50%). Other recurring categories include Cross-Site Request Forgery (CSRF).
1 of the records (50%) have a vendor fix, while 1 remain unpatched. The oldest unresolved one dates back to 2025.
2 independent researchers contributed these findings, one record each. OpenHook is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.3.10.
CVE-2025-62120OpenHook <= 4.3.1 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

OpenHook
Author
Rick Beckman
If you aren’t altogether comfortable with editing PHP files to customize your site, OpenHook is for you! An increasing number of themes & plugins come equipped with a myriad of hooks — points within their code which can receive user customizations, known as actions — which can be customized from within your WordPress admin panel using OpenHook! OpenHook brings the world of hooks & actions to the mainstream, providing an easy to use admin interface in which you can customize your site without limit, whether you’re using HTML/CSS/JavaScript or PHP! Features Customize the hooks present in your favorite themes! Define any hook you want within OpenHook and add an action to it! In addition to the themes which OpenHook supports explicitly, you can now use OpenHook to customize ANY hook (even something as arcane as theme_hook_before_meta_987) in ANY theme or plugin that has ANY hooks, from WordPress’ bare minimum hooks to hooks that are dynamically created and are as infinitely diverse as your site can be! Predefined hooks for Astra, the world’s most popular non-default WordPress theme! Also included are hooks for legacy themes Headway, Thesis 1.8.x, Flat, and K2. OpenBox, a PHP-friendly “box” for Thesis 2 Quick access to the header & footer hooks of WordPress All hooks can be customized with text, HTML/CSS/JavaScript, PHP, or shortcodes All actions can be selectively disabled A variety of actions already present in Flat, Thesis 1.8.x, and WordPress can be selectively disabled Hook visualization allows you to see exactly where each hook is fired on the front-end of your site Shortcodes [email], for masking email addresses from some spam robots [global], which makes use of custom fields on a draft page in order to provide a library of reusable strings [php], an admin-only shortcode for including PHP code within posts [snap], an easy way to include (nearly) always up-to-date screenshots of websites within your posts Ability to disable all shortcodes Display of phpinfo() in the admin panel Options management, including tools to upgrade from OpenHook 2 and to uninstall (delete) all OpenHook options Only users with the edit_themes permission may access OpenHook or its features. If enabled by such a user, other users may use [email] or [global] shortcodes in their entries as well. Compatible with ClassicPress!
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C