WordPress security by component
Ona
Plugin description
Ona is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published May 02, 2026; the highest CVE/CNA score is 9.9.
Plugin slug:
onaLatest vulnerability
CVE-2026-6812: Ona: Server-side request forgery
Ona is affected by server-side request forgery. Exploitation requires at least administrator-level access. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 1.26.
| Safe version |
|
||
|---|---|---|---|
| May 02, 2026 |
CVE-2026-6812
Ona: Server-side request forgery
Ona is affected by server-side request forgery. Exploitation requires at least administrator-level access. The vulnerable server can be induced to make attacker-selected network requests. The published affected range is <= 1.26.
|
> 1.26 |
CVE4.4
NVDPending
|
| Mar 25, 2026 |
CVE-2026-32482
Ona: Dangerous file upload
Ona is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is n/a through < 1.24.
|
1.24 |
CVE9.9
NVDPending
|