Impact
The Ocean Pro Demos and Ocean eComm Treasure Box plugins contain a stored cross‑site scripting vulnerability in the Popup Builder’s save_popup_content Ajax action. The flaw results from a lack of proper authorization checks, input sanitization, and output escaping. An attacker can supply malicious data through the 'content' parameter, which is then persisted to the database and rendered unfiltered inside a Gutenberg popup. When the popup is displayed, the injected script executes in the browser of any visitor, enabling credential theft, session hijacking, or defacement.
Affected Systems
OceanWP’s Ocean Pro Demos versions 1.5.4 and earlier, and Ocean eComm Treasure Box versions 1.8.0 and earlier are vulnerable. Exploitation requires an active premium license, the Popup Builder module enabled, and at least one published Gutenberg popup configured to appear on a page. Sites that do not meet these prerequisites are not affected.
Risk and Exploitability
This vulnerability has a CVSS score of 7.2, indicating high severity. The flaw is exploitable without authentication by sending a crafted request to the save_popup_content endpoint, after which any visitor to a page showing the affected popup will run the malicious code. The risk is greatest on sites with active premium licenses, the Popup Builder module enabled, and shown popups; disabling the module or removing the vulnerable content mitigates the threat.
OpenCVE Enrichment