Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oceanwp Ocean Extra ocean-extra allows Stored XSS.This issue affects Ocean Extra: from n/a through <= 2.4.8.
Published: 2025-06-06
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of user input during web page generation allows a stored cross‑site scripting (XSS) flaw in the Ocean Extra plugin. This weakness is a typical input validation error (CWE‑79) that can cause an attacker’s code to run in the browser of any victim who views a page containing the malicious data. The consequence is the potential compromise of confidentiality, integrity, or availability through cookie theft, session hijacking, defacement, or drive‑by infection, but it does not grant direct system control.

Affected Systems

The vulnerability exists in the Ocean Extra WordPress plugin for versions from at least 2.4.8 and earlier. Only installations running the plugin at or below version 2.4.8 are affected.

Risk and Exploitability

The CVSS score of 6.5 rates the vulnerability as moderate, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog, but it remains a valid attack surface. An attacker would need to inject malicious content that is subsequently stored and rendered—this could be achieved through any feature that accepts user‑supplied text, often requiring authenticated user privileges. Although the exploit is not trivial, patching is recommended to eliminate this stored XSS risk.

Generated by OpenCVE AI on April 30, 2026 at 12:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Ocean Extra to the latest version (2.4.9 or newer) where the input sanitization bug is fixed.
  • If an immediate update is not possible, configure the plugin or the site to strip or escape all user‑supplied HTML before storing it in the database.
  • As an additional safeguard, restrict or disable any post‑type or custom field that allows untrusted content to be displayed to visitors until the patch is applied.

Generated by OpenCVE AI on April 30, 2026 at 12:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17135 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.4.8.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.4.8. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oceanwp Ocean Extra ocean-extra allows Stored XSS.This issue affects Ocean Extra: from n/a through <= 2.4.8.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 06 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 11:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Extra allows Stored XSS.This issue affects Ocean Extra: from n/a through 2.4.8.
Title WordPress Ocean Extra plugin <= 2.4.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Oceanwp Ocean Extra
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:58.698Z

Reserved: 2025-05-30T14:04:49.665Z

Link: CVE-2025-49068

cve-icon Vulnrichment

Updated: 2025-06-06T16:00:39.898Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T12:15:24.407

Modified: 2026-04-23T15:31:16.400

Link: CVE-2025-49068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T12:30:16Z

Weaknesses