cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forthesis-openhook thesis-openhook

Direction: ascending
Jun 06, 2024

OpenHook # CVE-2023-5201

CVE, Research URL

CVE-2023-5201

Application

OpenHook

Date
Sep 30, 2023
Research Description
The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php] shortcode setting to be enabled on the vulnerable site.
Affected versions
max 4.3.1.
Status
vulnerable
Jan 10, 2026

OpenHook # CVE-2025-62120

CVE, Research URL

CVE-2025-62120

Application

OpenHook

Date
Dec 31, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Rick Beckman OpenHook allows Cross Site Request Forgery.This issue affects OpenHook: from n/a through 4.3.1.
Affected versions
max 4.3.1.
Status
vulnerable