XO Security
XO Security has one disclosed vulnerability in the WordSec catalog, all reported in 2017; it is fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for XO Security has a vendor fix available, so running the current release closes it.
All of these findings were reported by Plugin Vulnerabilities. XO Security is installed on roughly 30,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2017-18541XO Security < 1.5.3 - Cross-Site Scripting
Read the full analysisVulnerability Records

XO Security
Author
ishitaka
XO Security is a plugin to enhance login related security. This plugin does not write to .htaccess file. Besides Apache, LiteSpeed, Nginx and IIS also work. Functions Record login log. Limit login attempts. Add Captcha to the login form and comment form. Change the URL of the login page. Enable two-factor authentication (2FA) for login. Login Alert. Disable login by mail address. Disable login by user name. Change login error message. Disable XML-RPC and XML-RPC Pingback. Disable REST API. Disable author archive page. Remove comment author class of comments list. Remove the username from the oEmbed response data. WooCommerce login page protection. Anti-spam comment. Hide WordPress version information. Edit the author slug. Disable RSS and Atom feeds. Activate maintenance mode. Delete the readme.html file. WordPress multisite considerations If you set the login page separately for the main site and the subsite, you will not be able to use the password loss function of the subsite. We recommend that you set the login page to be common to all sites.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C