oceanwp records
18 published records for vendor oceanwp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 38.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-502 Deserialization of Untrusted Data1
- CWE-639 Authorization Bypass Through User-Controlled Key1
- CWE-862 Missing Authorization1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2025-3472Proof of concept | Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Executionoceanwp · ocean extra · CWE-94 | Critical9.8 | — | 2.0% | Apr 22, 2025 |
35Monitor | CVE-2023-49164No exploit | WordPress Ocean Extra Plugin <= 2.2.2 is vulnerable to Cross Site Request Forgery (CSRF)oceanwp · ocean extra · CWE-352 | High8.8 | — | 0.3% | Dec 19, 2023 |
30Monitor | CVE-2019-16250No exploit | includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Coceanwp · ocean extra · CWE-287 | High7.5 | — | 1.4% | Sep 11, 2019 |
30Monitor | CVE-2023-23700No exploit | WordPress OceanWP theme <= 3.4.1 - Authenticated Local File Inclusion vulnerabilityoceanwp · oceanwp · CWE-22 | High7.6 | — | 0.7% | May 17, 2024 |
28Monitor | CVE-2022-3374No exploit | Ocean Extra < 2.0.5 - Admin+ PHP Objection Injectionoceanwp · ocean extra · CWE-502 | High7.2 | — | 1.2% | Oct 31, 2022 |
26Monitor | CVE-2023-0749No exploit | Ocean Extra < 2.1.3 - Subscriber+ Arbitrary Post Content Disclosureoceanwp · ocean extra · CWE-639 | Medium6.5 | — | 0.7% | Mar 13, 2023 |
26Monitor | CVE-2022-35730No exploit | WordPress Oceanwp sticky header plugin <= 1.0.8 is vulnerable to Cross Site Request Forgery (CSRF)oceanwp · sticky header · CWE-352 | Medium6.5 | — | 0.3% | Dec 4, 2022 |
25Monitor | CVE-2024-3167No exploit | Ocean Extra <= 2.2.6 - Authenticated (Contributor+) Stored Cross-Site Scriptingoceanwp · ocean extra · CWE-79 | Medium6.4 | — | 0.5% | Apr 9, 2024 |
24Monitor | CVE-2021-25104Proof of concept | Ocean Extra < 1.9.5 - Reflected Cross-Site Scriptingoceanwp · ocean extra · CWE-79 | Medium6.1 | — | 1.4% | Jun 20, 2022 |
21Monitor | CVE-2024-1277No exploit | Ocean Extra <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scriptingoceanwp · ocean extra · CWE-79 | Medium5.4 | — | 0.5% | Feb 28, 2024 |
21Monitor | CVE-2023-24399No exploit | WordPress Ocean Extra Plugin <= 2.1.2 is vulnerable to Cross Site Scripting (XSS)oceanwp · ocean extra · CWE-79 | Medium5.4 | — | 0.3% | Mar 30, 2023 |
21Monitor | CVE-2023-23891No exploit | WordPress Ocean Extra Plugin <= 2.1.1 is vulnerable to Cross Site Scripting (XSS)oceanwp · ocean extra · CWE-79 | Medium5.4 | — | 0.3% | Apr 6, 2023 |
21Monitor | CVE-2024-37489No exploit | WordPress Ocean Extra plugin <= 2.2.9 - Authenticated Cross Site Scripting (XSS) vulnerabilityoceanwp · ocean extra · CWE-79 | Medium5.4 | — | 0.3% | Jul 21, 2024 |
21Monitor | CVE-2025-3458No exploit | Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ocean_gallery_id'oceanwp · ocean extra · CWE-79 | Medium5.4 | — | 0.3% | Apr 22, 2025 |
21Monitor | CVE-2025-3457No exploit | Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodeoceanwp · ocean extra · CWE-79 | Medium5.4 | — | 0.3% | Apr 22, 2025 |
17Monitor | CVE-2020-36760No exploit | Ocean Extra <=1.6.5 - Cross-Site Request Forgery Bypassoceanwp · ocean extra · CWE-352 | Medium4.3 | — | 0.6% | Jul 12, 2023 |
17Monitor | CVE-2025-8944No exploit | OceanWP < 4.1.2 - Subscriber+ Limited Option Updateoceanwp · oceanwp · CWE-862 | Medium4.3 | — | 0.2% | Sep 5, 2025 |
17Monitor | CVE-2025-8891No exploit | OceanWP <= 4.0.9 - 4.1.1 - Cross-Site Request Forgery to Ocean Extra Plugin Installationoceanwp · oceanwp · CWE-352 | Medium4.3 | — | 0.2% | Aug 13, 2025 |
- CVE-2025-347240Plan
Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution
CriticalCVSS 9.8Proof of conceptEPSS 2%oceanwp · ocean extraApr 22, 2025
- CVE-2023-4916435Monitor
WordPress Ocean Extra Plugin <= 2.2.2 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%oceanwp · ocean extraDec 19, 2023
- CVE-2019-1625030Monitor
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a C
HighCVSS 7.5No exploitEPSS 1%oceanwp · ocean extraSep 11, 2019
- CVE-2023-2370030Monitor
WordPress OceanWP theme <= 3.4.1 - Authenticated Local File Inclusion vulnerability
HighCVSS 7.6No exploitEPSS 1%oceanwp · oceanwpMay 17, 2024
- CVE-2022-337428Monitor
Ocean Extra < 2.0.5 - Admin+ PHP Objection Injection
HighCVSS 7.2No exploitEPSS 1%oceanwp · ocean extraOct 31, 2022
- CVE-2023-074926Monitor
Ocean Extra < 2.1.3 - Subscriber+ Arbitrary Post Content Disclosure
MediumCVSS 6.5No exploitEPSS 1%oceanwp · ocean extraMar 13, 2023
- CVE-2022-3573026Monitor
WordPress Oceanwp sticky header plugin <= 1.0.8 is vulnerable to Cross Site Request Forgery (CSRF)
MediumCVSS 6.5No exploitEPSS 0%oceanwp · sticky headerDec 4, 2022
- CVE-2024-316725Monitor
Ocean Extra <= 2.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 6.4No exploitEPSS 1%oceanwp · ocean extraApr 9, 2024
- CVE-2021-2510424Monitor
Ocean Extra < 1.9.5 - Reflected Cross-Site Scripting
MediumCVSS 6.1Proof of conceptEPSS 1%oceanwp · ocean extraJun 20, 2022
- CVE-2024-127721Monitor
Ocean Extra <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
MediumCVSS 5.4No exploitEPSS 0%oceanwp · ocean extraFeb 28, 2024
- CVE-2023-2439921Monitor
WordPress Ocean Extra Plugin <= 2.1.2 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%oceanwp · ocean extraMar 30, 2023
- CVE-2023-2389121Monitor
WordPress Ocean Extra Plugin <= 2.1.1 is vulnerable to Cross Site Scripting (XSS)
MediumCVSS 5.4No exploitEPSS 0%oceanwp · ocean extraApr 6, 2023
- CVE-2024-3748921Monitor
WordPress Ocean Extra plugin <= 2.2.9 - Authenticated Cross Site Scripting (XSS) vulnerability
MediumCVSS 5.4No exploitEPSS 0%oceanwp · ocean extraJul 21, 2024
- CVE-2025-345821Monitor
Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ocean_gallery_id'
MediumCVSS 5.4No exploitEPSS 0%oceanwp · ocean extraApr 22, 2025
- CVE-2025-345721Monitor
Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
MediumCVSS 5.4No exploitEPSS 0%oceanwp · ocean extraApr 22, 2025
- CVE-2020-3676017Monitor
Ocean Extra <=1.6.5 - Cross-Site Request Forgery Bypass
MediumCVSS 4.3No exploitEPSS 1%oceanwp · ocean extraJul 12, 2023
- CVE-2025-894417Monitor
OceanWP < 4.1.2 - Subscriber+ Limited Option Update
MediumCVSS 4.3No exploitEPSS 0%oceanwp · oceanwpSep 5, 2025
- CVE-2025-889117Monitor
OceanWP <= 4.0.9 - 4.1.1 - Cross-Site Request Forgery to Ocean Extra Plugin Installation
MediumCVSS 4.3No exploitEPSS 0%oceanwp · oceanwpAug 13, 2025