OceanWP <= 4.1.1 - Missing Authorization to Authenticated (Subscriber+) Settings Update
medium
The OceanWP theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ocean_update_search_box_light_mode AJAX action in all versions up to, and including, 4.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update t...
- CVSS:
- 4.3
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Aug 15, 2025
CVE-2025-8944 on NVD →
OceanWP <= 4.0.9 - 4.1.1 - Cross-Site Request Forgery to Ocean Extra Plugin Installation
medium
The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted...
- CVSS:
- 4.3
- Affected:
- 4.0.9 – 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Aug 12, 2025
CVE-2025-8891 on NVD →
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
medium
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-l...
- CVSS:
- 6.4
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.1
- Disclosed:
- Jul 2, 2025
CVE-2024-5647 on NVD →
OceanWP <= 4.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Select HTML Tag
medium
The OceanWP theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Select HTML tag in all versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary we...
- CVSS:
- 4.9
- Affected:
- up to 4.0.9
- Fixed in:
- 4.1.0
- Disclosed:
- Jun 18, 2025
CVE-2025-5524 on NVD →
OceanWP <= 3.5.4 - Missing Authorization to Sensitive Information Exposure via Limited Local File Inclusion
medium
The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_theme_panel_pane function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose sensitive information su...
- CVSS:
- 4.3
- Affected:
- up to 3.5.4
- Fixed in:
- 3.5.5
- Disclosed:
- Mar 28, 2024
CVE-2024-2476 on NVD →
OceanWP <= 3.4.1 - Authenticated (Subscriber+) Local File Inclusion
high
The OceanWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4. This allows subscriber-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive d...
- CVSS:
- 8.8
- Affected:
- up to 3.4.1
- Fixed in:
- 3.4.2
- Disclosed:
- Feb 27, 2023
CVE-2023-23700 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database