Description
The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2025-08-02
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting exploited via contributor‑level access
Action: Patch Now
AI Analysis

Impact

The Ocean Social Sharing plugin stores social icon titles without proper sanitization or escaping, allowing an authenticated user with Contributor or higher privileges to inject arbitrary JavaScript. The injected script executes in the context of any visitor who views the affected page, enabling session hijacking, data theft, or defacement. This vulnerability is a classic input‑validation weakness (CWE‑79) that can compromise confidentiality, integrity, and availability for the entire website.

Affected Systems

OceanWP Ocean Social Sharing plugin versions up to and including 2.2.1 on WordPress sites. No other vendors or products are affected.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity. The EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation in the near term, and the issue is not listed in the CISA KEV catalog. The most probable attack path involves a contributor editing a social icon title in the WordPress admin interface, which then gets rendered on the front‑end. Patching the plugin removes the storage vector and eliminates the risk.

Generated by OpenCVE AI on April 21, 2026 at 03:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Ocean Social Sharing to the latest version or to at least 2.2.2.
  • Restrict the Contributor role to trusted users and review user‑role assignments.
  • If an update is not immediately possible, deactivate the plugin to stop the vulnerability from being exploitable.

Generated by OpenCVE AI on April 21, 2026 at 03:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-23434 The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

Mon, 04 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 04 Aug 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Oceanwp
Oceanwp ocean Social Sharing
Wordpress
Wordpress wordpress
Vendors & Products Oceanwp
Oceanwp ocean Social Sharing
Wordpress
Wordpress wordpress

Sat, 02 Aug 2025 11:30:00 +0000

Type Values Removed Values Added
Description The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Ocean Social Sharing <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Oceanwp Ocean Social Sharing
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:01:32.100Z

Reserved: 2025-07-11T17:47:22.266Z

Link: CVE-2025-7500

cve-icon Vulnrichment

Updated: 2025-08-04T15:16:26.159Z

cve-icon NVD

Status : Deferred

Published: 2025-08-02T12:15:28.050

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-7500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-21T03:45:27Z

Weaknesses