plugin

Ocean Extra Vulnerabilities

53 known security issues reported for the Ocean Extra WordPress plugin. Most recent disclosed Apr 30, 2026.

2 high 19 medium

Running Ocean Extra on your site? Check whether your installed version is affected.

Scan your site free

Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter

medium

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 2.4.2
Fixed in:
2.4.4
Disclosed:
Apr 30, 2026

CVE-2024-13362 on NVD →

Ocean Extra <= 2.5.3 - Missing Authorization

medium

The Ocean Extra plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.5.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.5.3
Fixed in:
2.5.4
Disclosed:
Apr 7, 2026

CVE-2026-34903 on NVD →

Ocean Extra <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via oceanwp_library Shortcode

medium

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's oceanwp_library shortcode in all versions up to, and including, 2.4.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contri...

CVSS:
6.4
Affected:
up to 2.4.9
Fixed in:
2.5.0
Disclosed:
Aug 29, 2025

CVE-2025-9499 on NVD →

Ocean Extra [ocean-extra] < 2.4.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.4.8.

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Jun 6, 2025

CVE-2025-49068 on NVD →

Ocean Extra <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages...

CVSS:
5.4
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
Jun 2, 2025

CVE-2025-49068 on NVD →

Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution

medium

The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to ex...

CVSS:
6.5
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Apr 21, 2025

CVE-2025-3472 on NVD →

Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'oceanwp_icon' shortcode in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contrib...

CVSS:
6.4
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Apr 21, 2025

CVE-2025-3457 on NVD →

Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ocean_gallery_id'

medium

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ocean_gallery_id’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to i...

CVSS:
6.4
Affected:
up to 2.4.6
Fixed in:
2.4.7
Disclosed:
Apr 21, 2025

CVE-2025-3458 on NVD →

Ocean Extra [ocean-extra] < 1.9.4

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 1.9.4
Fixed in:
1.9.4
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

Ocean Extra [ocean-extra] < 2.3.0

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.2.9.

Affected:
up to 2.3.0
Fixed in:
2.3.0
Disclosed:
Jul 21, 2024

CVE-2024-37489 on NVD →

Ocean Extra <= 2.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that...

CVSS:
6.4
Affected:
up to 2.2.9
Fixed in:
2.3.0
Disclosed:
Jul 4, 2024

CVE-2024-37489 on NVD →

Ocean Extra [ocean-extra] < 2.2.9

unknown

[en] The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level acce...

Affected:
up to 2.2.9
Fixed in:
2.2.9
Disclosed:
Jun 11, 2024

CVE-2024-5531 on NVD →

Ocean Extra <= 2.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Flickr Widget

medium

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access an...

CVSS:
6.4
Affected:
up to 2.2.8
Fixed in:
2.2.9
Disclosed:
Jun 10, 2024

CVE-2024-5531 on NVD →

Ocean Extra [ocean-extra] < 2.2.7

unknown

[en] The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘twitter_username’ parameter in versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above...

Affected:
up to 2.2.7
Fixed in:
2.2.7
Disclosed:
Apr 9, 2024

CVE-2024-3167 on NVD →

Ocean Extra <= 2.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘twitter_username’ parameter in versions up to, and including, 2.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to...

CVSS:
6.4
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Apr 8, 2024

CVE-2024-3167 on NVD →

Ocean Extra [ocean-extra] < 2.2.5

unknown

[en] The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom fields in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web...

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Feb 20, 2024

CVE-2024-1277 on NVD →

Ocean Extra <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom fields in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scrip...

CVSS:
6.4
Affected:
up to 2.2.4
Fixed in:
2.2.5
Disclosed:
Feb 16, 2024

CVE-2024-1277 on NVD →

Ocean Extra [ocean-extra] < 2.2.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Dec 19, 2023

CVE-2023-49164 on NVD →

Ocean Extra <= 2.2.2 - Cross-Site Request Forgery to Arbitrary Plugin Activation

medium

The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.2. This is due to missing or incorrect nonce validation on the ajax_required_plugins_activate() function. This makes it possible for unauthenticated attackers to activate arbitrary plugins via a fo...

CVSS:
4.3
Affected:
up to 2.2.2
Fixed in:
2.2.3
Disclosed:
Nov 28, 2023

CVE-2023-49164 on NVD →

Ocean Extra [ocean-extra] < 2.2.3

unknown

The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.2. This is due to missing or incorrect nonce validation on the ajax_required_plugins_activate() function. This makes it possible for unauthenticated attackers to activate arbitrary plugins via a fo...

Affected:
up to 2.2.3
Fixed in:
2.2.3
Disclosed:
Nov 28, 2023

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
1.5.12 – 2.1.6
Fixed in:
2.1.8
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Ocean Extra [ocean-extra] < 1.6.6

unknown

[en] The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles...

Affected:
up to 1.6.6
Fixed in:
1.6.6
Disclosed:
Jul 12, 2023

CVE-2020-36760 on NVD →

Ocean Extra [ocean-extra] < 1.6.6

unknown
Affected:
up to 1.6.6
Fixed in:
1.6.6
Disclosed:
Jun 7, 2023

CVE-2021-4342 on NVD →

Ocean Extra [ocean-extra] < 2.1.3

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.1 versions. Needs the OceanWP theme installed and activated.

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Apr 6, 2023

CVE-2023-23891 on NVD →

Ocean Extra [ocean-extra] < 2.1.3

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.2 versions.

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Mar 30, 2023

CVE-2023-24399 on NVD →

Ocean Extra [ocean-extra] < 2.1.3

unknown

[en] The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Mar 13, 2023

CVE-2023-0749 on NVD →

Ocean Extra <= 2.1.2 - Authenticated (Subscriber+) Arbitrary Post Access

medium

The Ocean Extra for WordPress is vulnerable to disclosure of potentially sensitive data in versions up to, and including, 2.1.2. This is due to to the [oceanwp_library] shortcode not properly validating a post's status prior to returning the post's content. This makes it possible for authenticated attackers with subscr...

CVSS:
6.5
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Feb 14, 2023

CVE-2023-0749 on NVD →

Ocean Extra <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and ab...

CVSS:
6.4
Affected:
up to 2.1.2
Fixed in:
2.1.3
Disclosed:
Feb 14, 2023

CVE-2023-24399 on NVD →

Ocean Extra [ocean-extra] < 2.1.3

unknown

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and ab...

Affected:
up to 2.1.3
Fixed in:
2.1.3
Disclosed:
Feb 14, 2023

Ocean Extra <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and ab...

CVSS:
6.4
Affected:
up to 2.1.1
Fixed in:
2.1.2
Disclosed:
Feb 1, 2023

CVE-2023-23891 on NVD →

Ocean Extra [ocean-extra] < 2.1.2

unknown

The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and ab...

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Feb 1, 2023

Ocean Extra [ocean-extra] < 2.0.5

unknown

[en] The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

Affected:
up to 2.0.5
Fixed in:
2.0.5
Disclosed:
Oct 31, 2022

CVE-2022-3374 on NVD →

Ocean Extra <= 2.0.4 - Authenticated (Administrator+) PHP Object Injection

high

The Ocean Extra plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.4 via deserialization of untrusted input when processing a malicious customizer styling file. This allows administrator-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plug...

CVSS:
7.2
Affected:
up to 2.0.4
Fixed in:
2.0.5
Disclosed:
Oct 10, 2022

CVE-2022-3374 on NVD →

Ocean Extra [ocean-extra] < 1.9.5

unknown

[en] The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue

Affected:
up to 1.9.5
Fixed in:
1.9.5
Disclosed:
Jun 20, 2022

CVE-2021-25104 on NVD →

Ocean Extra <= 1.9.4 - Reflected Cross-Site Scripting

medium

The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue

CVSS:
6.1
Affected:
up to 1.9.5
Fixed in:
1.9.5
Disclosed:
May 24, 2022

CVE-2021-25104 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 1.9.4
Fixed in:
1.9.4
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

Ocean Extra [ocean-extra] < 1.9.4

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 1.9.4
Fixed in:
1.9.4
Disclosed:
Mar 4, 2022

Ocean Extra [ocean-extra] < 1.9.4

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Ocean Extra plugin (versions < 1.9.4).

Affected:
up to 1.9.4
Fixed in:
1.9.4
Disclosed:
Feb 28, 2022

Ocean Extra [ocean-extra] < 1.9.4

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Ocean Extra plugin (versions < 1.9.4).

Affected:
up to 1.9.4
Fixed in:
1.9.4
Disclosed:
Feb 28, 2022

Ocean Extra <=1.6.5 - Cross-Site Request Forgery Bypass

medium

The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles via...

CVSS:
4.3
Affected:
up to 1.6.6
Fixed in:
1.6.6
Disclosed:
Sep 26, 2020

CVE-2020-36760 on NVD →

Ocean Extra [ocean-extra] < 1.6.6

unknown

Cross-Site Request Forgery (CSRF) vulnerability found by Jerome Bruandet (NinTechNet) in WordPress Ocean Extra plugin (versions <= 1.6.5).

Affected:
up to 1.6.6
Fixed in:
1.6.6
Disclosed:
Sep 16, 2020

Ocean Extra [ocean-extra] < 1.5.9

unknown

[en] includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.

Affected:
up to 1.5.9
Fixed in:
1.5.9
Disclosed:
Sep 11, 2019

CVE-2019-16250 on NVD →

Ocean Extra [ocean-extra] < 1.5.9

unknown

Unauthenticated CSS injection vulnerability found by Jerome Bruandet in WordPress Ocean Extra plugin (versions <= 1.5.8).

Affected:
up to 1.5.9
Fixed in:
1.5.9
Disclosed:
Jul 4, 2019

Ocean Extra [ocean-extra] < 1.5.9

unknown

Unauthenticated Settings change vulnerability found by Jerome Bruandet in WordPress Ocean Extra plugin (versions <= 1.5.8).

Affected:
up to 1.5.9
Fixed in:
1.5.9
Disclosed:
Jul 4, 2019

Ocean Extra <= 1.5.7 - Unauthenticated Options update and CSS injection

high

includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.

CVSS:
7.5
Affected:
up to 1.5.8
Fixed in:
1.5.9
Disclosed:
Jul 3, 2019

CVE-2019-16250 on NVD →

Ocean Extra [ocean-extra] < 1.9.4

unknown

The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a...

Affected:
up to 1.9.4
Fixed in:
1.9.4

Ocean Extra [ocean-extra] < 1.6.6

unknown

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Affected:
up to 1.6.6
Fixed in:
1.6.6

Ocean Extra [ocean-extra] < 2.1.3

unknown

The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 2.1.3
Fixed in:
2.1.3

Ocean Extra [ocean-extra] < 2.1.8

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 2.1.8
Fixed in:
2.1.8

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database