← WordPress Vulnerabilities
WordPress security by component

Ona

Ona is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published May 02, 2026; the highest CVE/CNA score is 9.9.

Plugin slug: ona

CVE-2026-6812: Ona: Server-side request forgery

Ona is affected by server-side request forgery. Exploitation requires at least administrator-level access. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 1.26.

PublishedMay 02, 2026
Known safe version> 1.26
Safe version
May 02, 2026 CVE-2026-6812
Ona: Server-side request forgery
Ona is affected by server-side request forgery. Exploitation requires at least administrator-level access. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 1.26.
> 1.26
CVE4.4
NVDPending
Mar 25, 2026 CVE-2026-32482
Ona: Dangerous file upload
Ona is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through < 1.24.
1.24
CVE9.9
NVDPending