Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2022-3374

Disclosure Date: October 31, 2022 (last updated December 22, 2024)
The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.
Attacker Value
Unknown

CVE-2021-25104

Disclosure Date: June 20, 2022 (last updated October 07, 2023)
The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2019-16250

Disclosure Date: September 11, 2019 (last updated November 27, 2024)
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.