XO Security

XO Security has one disclosed vulnerability in the WordSec catalog, all reported in 2017; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for XO Security has a vendor fix available, so running the current release closes it.

All of these findings were reported by Plugin Vulnerabilities. XO Security is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all XO Security vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.1CVE-2017-18541

XO Security < 1.5.3 - Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Showing 1–1 of 1 reports
XO Security banner
Latestv3.11.0

XO Security

ishitaka

Author

ishitaka

5.0(11)
100/100
Last Updated
2026-07-19 (2mo ago)
Active Installs
30,000+
Downloads
406,149
Requires WP
6.0+
Requires PHP
7.2+
Tested up to
WP 7.0.4
Created
2016-01-18 (11y ago)

XO Security is a plugin to enhance login related security. This plugin does not write to .htaccess file. Besides Apache, LiteSpeed, Nginx and IIS also work. Functions Record login log. Limit login attempts. Add Captcha to the login form and comment form. Change the URL of the login page. Enable two-factor authentication (2FA) for login. Login Alert. Disable login by mail address. Disable login by user name. Change login error message. Disable XML-RPC and XML-RPC Pingback. Disable REST API. Disable author archive page. Remove comment author class of comments list. Remove the username from the oEmbed response data. WooCommerce login page protection. Anti-spam comment. Hide WordPress version information. Edit the author slug. Disable RSS and Atom feeds. Activate maintenance mode. Delete the readme.html file. WordPress multisite considerations If you set the login page separately for the main site and the subsite, you will not be able to use the password loss function of the subsite. We recommend that you set the login page to be common to all sites.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C