Description
The Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter in all versions up to, and including, 1.5.4, and 1.8.0, respectively, due to insufficient authorization, input sanitization, and output escaping in the Popup Builder's save_popup_content AJAX action. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into a published Gutenberg popup that will execute whenever a user accesses a page on which the popup is configured to display. A valid premium license, the Popup Builder module, and at least one published Gutenberg popup configured for display are required.
Published: 2026-10-09
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (CWE‑79)
Action: Patch Immediately
AI Analysis

Impact

The Ocean Pro Demos and Ocean eComm Treasure Box plugins contain a stored cross‑site scripting vulnerability in the Popup Builder’s save_popup_content Ajax action. The flaw results from a lack of proper authorization checks, input sanitization, and output escaping. An attacker can supply malicious data through the 'content' parameter, which is then persisted to the database and rendered unfiltered inside a Gutenberg popup. When the popup is displayed, the injected script executes in the browser of any visitor, enabling credential theft, session hijacking, or defacement.

Affected Systems

OceanWP’s Ocean Pro Demos versions 1.5.4 and earlier, and Ocean eComm Treasure Box versions 1.8.0 and earlier are vulnerable. Exploitation requires an active premium license, the Popup Builder module enabled, and at least one published Gutenberg popup configured to appear on a page. Sites that do not meet these prerequisites are not affected.

Risk and Exploitability

This vulnerability has a CVSS score of 7.2, indicating high severity. The flaw is exploitable without authentication by sending a crafted request to the save_popup_content endpoint, after which any visitor to a page showing the affected popup will run the malicious code. The risk is greatest on sites with active premium licenses, the Popup Builder module enabled, and shown popups; disabling the module or removing the vulnerable content mitigates the threat.

Generated by OpenCVE AI on October 9, 2026 at 09:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest updates to Ocean Pro Demos (1.5.5+) and Ocean eComm Treasure Box (1.8.1+).
  • If the Popup Builder module is not required, disable or deactivate it to remove the vulnerable endpoint.
  • Review all existing Gutenberg popups and delete or clean any content that may contain stored XSS payloads.

Generated by OpenCVE AI on October 9, 2026 at 09:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter in all versions up to, and including, 1.5.4, and 1.8.0, respectively, due to insufficient authorization, input sanitization, and output escaping in the Popup Builder's save_popup_content AJAX action. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into a published Gutenberg popup that will execute whenever a user accesses a page on which the popup is configured to display. A valid premium license, the Popup Builder module, and at least one published Gutenberg popup configured for display are required.
Title Ocean Pro Demos <= 1.5.4 and Ocean eComm Treasure Box <= 1.8.0 - Unauthenticated Stored Cross-Site Scripting via 'content' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-09T15:12:28.103Z

Reserved: 2026-08-27T18:41:48.090Z

Link: CVE-2026-81929

cve-icon Vulnrichment

Updated: 2026-10-09T15:01:06.247Z

cve-icon NVD

Status : Deferred

Published: 2026-10-09T07:17:18.600

Modified: 2026-10-09T16:17:30.913

Link: CVE-2026-81929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T09:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')