Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown
CVE-2022-3374
Disclosure Date: October 31, 2022 (last updated December 22, 2024)
The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.
0
Attacker Value
Unknown
CVE-2021-25104
Disclosure Date: June 20, 2022 (last updated October 07, 2023)
The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2019-16250
Disclosure Date: September 11, 2019 (last updated November 27, 2024)
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.
0