The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 19 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution. | |
| Title | Ocean Modal Window < 2.3.3 - Editor+ Remote Code Execution via Modal Conditions | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-12-19T06:00:06.104Z
Reserved: 2025-11-17T14:26:04.115Z
Link: CVE-2025-13307
No data.
Status : Received
Published: 2025-12-19T06:15:50.837
Modified: 2025-12-19T06:15:50.837
Link: CVE-2025-13307
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.