Unknown Ocean Extra vulnerabilities
3 known vulnerabilities affecting unknown/ocean_extra.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-0749MEDIUMCVSS 6.5fixed in 2.1.32023-03-13
CVE-2023-0749 [MEDIUM] CWE-639 CVE-2023-0749: The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a s
The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.
cvelistv5nvd
CVE-2022-3374HIGHCVSS 7.2≥ 2.0.5, < 2.0.52022-10-31
CVE-2022-3374 [HIGH] CWE-502 CVE-2022-3374: The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which co
The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.
cvelistv5nvd
CVE-2021-25104MEDIUMCVSS 6.1PoC≥ 1.9.5, < 1.9.52022-06-20
CVE-2021-25104 [MEDIUM] CWE-79 CVE-2021-25104: The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used wh
The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue
cvelistv5nvd