Description
WordPress Plugin Ocean Extra is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently modify some settings. WordPress Plugin Ocean Extra version 1.5.8 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.5.10 or latest
References
https://blog.nintechnet.com/settings-change-and-css-injection-in-wordpress-ocean-extra-plugin/
https://wordpress.org/support/topic/latest-update-contains-security-fixes/
https://plugins.trac.wordpress.org/browser/ocean-extra/trunk/readme.txt?rev=2117702
Related Vulnerabilities
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2023-39456)
Jboss EAP Deserialization of Untrusted Data Vulnerability (CVE-2016-3690)
Drupal Core 8.9.x Cross-Site Scripting (8.9.0 - 8.9.15)
WordPress Plugin Analytics Cross-Site Scripting (1.2.3)
Liferay DXP Missing Authorization Vulnerability (CVE-2025-62256)