WP OER

WP OER has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for WP OER has a vendor fix available, so running the current release closes it.

WP OER is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.2.11.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all WP OER vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1

WP OER <= 0.9.0 - Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
2022-06-17 00:00N/A
6.1
Medium
AnonymousYes
Showing 1–1 of 1 reports
WP OER banner
Latestv0.9.3
5.0(1)
100/100
Last Updated
2023-05-12 (3y ago)
Active Installs
10+
Downloads
11,630
Requires WP
5.0+
Requires PHP
7.0+
Tested up to
WP 6.2.11
Created
2017-08-16 (9y ago)

WP OER is a free plugin which allows you to create your own open educational resource repository on any WordPress website. Why pay for a proprietary system with limited options? WP OER is customizable, easy to use, and free. Open Educational Resources (OER) are freely accessible, openly licensed documents and media useful for teaching, learning, and assessing as well as for research purposes. Alternative and more flexible licensing options have become available as a result of the work of Creative Commons, an organization providing ready-made licensing agreements less restrictive than the “all rights reserved” terms of standard international copyright. These new options have become a “critical infrastructure service for the OER movement.” Another license, typically used by developers of OER software, is the GNU General Public License from the free and open-source software (FOSS) community. More information about Open Education and the U.S. Department of Education’s #GoOpen campaign can be found on the Office of Educational Technology’s website. This project has been funded at least or in part with Federal funds from the U.S. Department of Education under Contract Number ED-OOS-13-R-0064. The content of this publication does not necessarily reflect the views or policies of the U.S. Department of Education nor does mention of trade names, commercial products, or organizations imply endorsement by the U.S. Government.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C