theme

Oceanwp Vulnerabilities

6 known security issues reported for the Oceanwp WordPress theme. Most recent disclosed Aug 15, 2025.

1 high 5 medium

Running Oceanwp on your site? Check whether your installed version is affected.

Scan your site free

OceanWP <= 4.1.1 - Missing Authorization to Authenticated (Subscriber+) Settings Update

medium

The OceanWP theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ocean_update_search_box_light_mode AJAX action in all versions up to, and including, 4.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update t...

CVSS:
4.3
Affected:
up to 4.1.1
Fixed in:
4.1.2
Disclosed:
Aug 15, 2025

CVE-2025-8944 on NVD →

OceanWP <= 4.0.9 - 4.1.1 - Cross-Site Request Forgery to Ocean Extra Plugin Installation

medium

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted...

CVSS:
4.3
Affected:
4.0.9 – 4.1.1
Fixed in:
4.1.2
Disclosed:
Aug 12, 2025

CVE-2025-8891 on NVD →

Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library

medium

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...

CVSS:
6.4
Affected:
up to 3.6.0
Fixed in:
3.6.1
Disclosed:
Jul 2, 2025

CVE-2024-5647 on NVD →

OceanWP <= 4.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Select HTML Tag

medium

The OceanWP theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Select HTML tag in all versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary we...

CVSS:
4.9
Affected:
up to 4.0.9
Fixed in:
4.1.0
Disclosed:
Jun 18, 2025

CVE-2025-5524 on NVD →

OceanWP <= 3.5.4 - Missing Authorization to Sensitive Information Exposure via Limited Local File Inclusion

medium

The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_theme_panel_pane function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose sensitive information su...

CVSS:
4.3
Affected:
up to 3.5.4
Fixed in:
3.5.5
Disclosed:
Mar 28, 2024

CVE-2024-2476 on NVD →

OceanWP <= 3.4.1 - Authenticated (Subscriber+) Local File Inclusion

high

The OceanWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4. This allows subscriber-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive d...

CVSS:
8.8
Affected:
up to 3.4.1
Fixed in:
3.4.2
Disclosed:
Feb 27, 2023

CVE-2023-23700 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database