Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter
medium
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.4
- Disclosed:
- Apr 30, 2026
CVE-2024-13362 on NVD →
Ocean Extra <= 2.5.3 - Missing Authorization
medium
The Ocean Extra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.5.3
- Fixed in:
- 2.5.4
- Disclosed:
- Apr 7, 2026
CVE-2026-34903 on NVD →
Ocean Extra <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via oceanwp_library Shortcode
medium
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's oceanwp_library shortcode in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...
- CVSS:
- 6.4
- Affected:
- up to 2.4.9
- Fixed in:
- 2.5.0
- Disclosed:
- Aug 29, 2025
CVE-2025-9499 on NVD →
Ocean Extra [ocean-extra] < 2.4.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.4.8.
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- Jun 6, 2025
CVE-2025-49068 on NVD →
Ocean Extra <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages...
- CVSS:
- 5.4
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.9
- Disclosed:
- Jun 2, 2025
CVE-2025-49068 on NVD →
Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution
medium
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to ex...
- CVSS:
- 6.5
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Apr 21, 2025
CVE-2025-3472 on NVD →
Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contrib...
- CVSS:
- 6.4
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Apr 21, 2025
CVE-2025-3457 on NVD →
Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ocean_gallery_id'
medium
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to i...
- CVSS:
- 6.4
- Affected:
- up to 2.4.6
- Fixed in:
- 2.4.7
- Disclosed:
- Apr 21, 2025
CVE-2025-3458 on NVD →
Ocean Extra [ocean-extra] < 1.9.4
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.4
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
Ocean Extra [ocean-extra] < 2.3.0
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.2.9.
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.0
- Disclosed:
- Jul 21, 2024
CVE-2024-37489 on NVD →
Ocean Extra <= 2.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...
- CVSS:
- 6.4
- Affected:
- up to 2.2.9
- Fixed in:
- 2.3.0
- Disclosed:
- Jul 4, 2024
CVE-2024-37489 on NVD →
Ocean Extra [ocean-extra] < 2.2.9
unknown
[en] The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level acce...
- Affected:
- up to 2.2.9
- Fixed in:
- 2.2.9
- Disclosed:
- Jun 11, 2024
CVE-2024-5531 on NVD →
Ocean Extra <= 2.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flickr Widget
medium
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access an...
- CVSS:
- 6.4
- Affected:
- up to 2.2.8
- Fixed in:
- 2.2.9
- Disclosed:
- Jun 10, 2024
CVE-2024-5531 on NVD →
Ocean Extra [ocean-extra] < 2.2.7
unknown
[en] The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘twitter_username’ parameter in versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above...
- Affected:
- up to 2.2.7
- Fixed in:
- 2.2.7
- Disclosed:
- Apr 9, 2024
CVE-2024-3167 on NVD →
Ocean Extra <= 2.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘twitter_username’ parameter in versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to...
- CVSS:
- 6.4
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.7
- Disclosed:
- Apr 8, 2024
CVE-2024-3167 on NVD →
Ocean Extra [ocean-extra] < 2.2.5
unknown
[en] The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom fields in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web...
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Feb 20, 2024
CVE-2024-1277 on NVD →
Ocean Extra <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom fields in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 2.2.4
- Fixed in:
- 2.2.5
- Disclosed:
- Feb 16, 2024
CVE-2024-1277 on NVD →
Ocean Extra [ocean-extra] < 2.2.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Dec 19, 2023
CVE-2023-49164 on NVD →
Ocean Extra <= 2.2.2 - Cross-Site Request Forgery to Arbitrary Plugin Activation
medium
The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.2. This is due to missing or incorrect nonce validation on the ajax_required_plugins_activate() function. This makes it possible for unauthenticated attackers to activate arbitrary plugins via a fo...
- CVSS:
- 4.3
- Affected:
- up to 2.2.2
- Fixed in:
- 2.2.3
- Disclosed:
- Nov 28, 2023
CVE-2023-49164 on NVD →
Ocean Extra [ocean-extra] < 2.2.3
unknown
The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.2. This is due to missing or incorrect nonce validation on the ajax_required_plugins_activate() function. This makes it possible for unauthenticated attackers to activate arbitrary plugins via a fo...
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.3
- Disclosed:
- Nov 28, 2023
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 1.5.12 – 2.1.6
- Fixed in:
- 2.1.8
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Ocean Extra [ocean-extra] < 1.6.6
unknown
[en] The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles...
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Jul 12, 2023
CVE-2020-36760 on NVD →
Ocean Extra [ocean-extra] < 1.6.6
unknown
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Jun 7, 2023
CVE-2021-4342 on NVD →
Ocean Extra [ocean-extra] < 2.1.3
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.1 versions. Needs the OceanWP theme installed and activated.
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Apr 6, 2023
CVE-2023-23891 on NVD →
Ocean Extra [ocean-extra] < 2.1.3
unknown
[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.2 versions.
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Mar 30, 2023
CVE-2023-24399 on NVD →
Ocean Extra [ocean-extra] < 2.1.3
unknown
[en] The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Mar 13, 2023
CVE-2023-0749 on NVD →
Ocean Extra <= 2.1.2 - Authenticated (Subscriber+) Arbitrary Post Access
medium
The Ocean Extra for WordPress is vulnerable to disclosure of potentially sensitive data in versions up to, and including, 2.1.2. This is due to to the [oceanwp_library] shortcode not properly validating a post's status prior to returning the post's content. This makes it possible for authenticated attackers with subscr...
- CVSS:
- 6.5
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Feb 14, 2023
CVE-2023-0749 on NVD →
Ocean Extra <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and ab...
- CVSS:
- 6.4
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.3
- Disclosed:
- Feb 14, 2023
CVE-2023-24399 on NVD →
Ocean Extra [ocean-extra] < 2.1.3
unknown
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and ab...
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
- Disclosed:
- Feb 14, 2023
Ocean Extra <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and ab...
- CVSS:
- 6.4
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Feb 1, 2023
CVE-2023-23891 on NVD →
Ocean Extra [ocean-extra] < 2.1.2
unknown
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and ab...
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Feb 1, 2023
Ocean Extra [ocean-extra] < 2.0.5
unknown
[en] The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.
- Affected:
- up to 2.0.5
- Fixed in:
- 2.0.5
- Disclosed:
- Oct 31, 2022
CVE-2022-3374 on NVD →
Ocean Extra <= 2.0.4 - Authenticated (Administrator+) PHP Object Injection
high
The Ocean Extra plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.4 via deserialization of untrusted input when processing a malicious customizer styling file. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plug...
- CVSS:
- 7.2
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.5
- Disclosed:
- Oct 10, 2022
CVE-2022-3374 on NVD →
Ocean Extra [ocean-extra] < 1.9.5
unknown
[en] The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- Jun 20, 2022
CVE-2021-25104 on NVD →
Ocean Extra <= 1.9.4 - Reflected Cross-Site Scripting
medium
The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue
- CVSS:
- 6.1
- Affected:
- up to 1.9.5
- Fixed in:
- 1.9.5
- Disclosed:
- May 24, 2022
CVE-2021-25104 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.4
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
Ocean Extra [ocean-extra] < 1.9.4
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.4
- Disclosed:
- Mar 4, 2022
Ocean Extra [ocean-extra] < 1.9.4
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Ocean Extra plugin (versions < 1.9.4).
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.4
- Disclosed:
- Feb 28, 2022
Ocean Extra [ocean-extra] < 1.9.4
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress Ocean Extra plugin (versions < 1.9.4).
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.4
- Disclosed:
- Feb 28, 2022
Ocean Extra <=1.6.5 - Cross-Site Request Forgery Bypass
medium
The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles via...
- CVSS:
- 4.3
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Sep 26, 2020
CVE-2020-36760 on NVD →
Ocean Extra [ocean-extra] < 1.6.6
unknown
Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Ocean Extra plugin (versions <= 1.6.5).
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Sep 16, 2020
Ocean Extra [ocean-extra] < 1.5.9
unknown
[en] includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.
- Affected:
- up to 1.5.9
- Fixed in:
- 1.5.9
- Disclosed:
- Sep 11, 2019
CVE-2019-16250 on NVD →
Ocean Extra [ocean-extra] < 1.5.9
unknown
Unauthenticated CSS injection vulnerability found by Jerome Bruandet in WordPress Ocean Extra plugin (versions <= 1.5.8).
- Affected:
- up to 1.5.9
- Fixed in:
- 1.5.9
- Disclosed:
- Jul 4, 2019
Ocean Extra [ocean-extra] < 1.5.9
unknown
Unauthenticated Settings change vulnerability found by Jerome Bruandet in WordPress Ocean Extra plugin (versions <= 1.5.8).
- Affected:
- up to 1.5.9
- Fixed in:
- 1.5.9
- Disclosed:
- Jul 4, 2019
Ocean Extra <= 1.5.7 - Unauthenticated Options update and CSS injection
high
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.
- CVSS:
- 7.5
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.9
- Disclosed:
- Jul 3, 2019
CVE-2019-16250 on NVD →
Ocean Extra [ocean-extra] < 2.4.7
unknown
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
CVE-2025-3472 on NVD →
Ocean Extra [ocean-extra] < 2.4.7
unknown
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
CVE-2025-3458 on NVD →
Ocean Extra [ocean-extra] < 2.4.7
unknown
- Affected:
- up to 2.4.7
- Fixed in:
- 2.4.7
CVE-2025-3457 on NVD →
Ocean Extra [ocean-extra] < 1.9.4
unknown
The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a...
- Affected:
- up to 1.9.4
- Fixed in:
- 1.9.4
Ocean Extra [ocean-extra] < 2.5.0
unknown
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.0
CVE-2025-9499 on NVD →
Ocean Extra [ocean-extra] < 1.6.6
unknown
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
Ocean Extra [ocean-extra] < 2.1.3
unknown
The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.3
Ocean Extra [ocean-extra] < 2.1.8
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 2.1.8
- Fixed in:
- 2.1.8
CVE-2023-33999 on NVD →