Description
Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.
Published: 2026-09-23
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The Ocean Extra plugin for WordPress contains a contributor‑level cross‑site scripting flaw in all releases up to 2.6.1. An attacker who has contributor privileges can inject malicious JavaScript into the plugin’s configuration or content fields, which is then rendered in the front‑end of the site. This type of flaw can be used to steal credentials, deface pages, or serve malware to visitors. The vulnerability is categorized as CWE‑79, which represents a reflected or stored XSS weakness.

Affected Systems

This issue affects the WordPress Ocean Extra plugin provided by OceanWP. All versions 2.6.1 and earlier are vulnerable. Site owners running these versions on a WordPress installation must upgrade the plugin or otherwise mitigate the risk.

Risk and Exploitability

The CVSS score of 6.5 places this as a medium‑severity vulnerability. No EPSS score is available, so the current exploitation probability remains unclear, but the CWE‑79 classification indicates that an attacker who can coerce a contributor can potentially influence page content. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation at present; nevertheless, the potential for unauthorized data disclosure or remote code execution via injected JavaScript warrants prompt remediation.

Generated by OpenCVE AI on September 23, 2026 at 20:07 UTC.

Remediation

Vendor Solution

Update the WordPress Ocean Extra plugin to the latest available version (at least 2.6.2).


OpenCVE Recommended Actions

  • Upgrade the Ocean Extra plugin to version 2.6.2 or newer.
  • If updating immediately is not possible, remove or restrict WordPress contributor roles to limit potential injection points.
  • Configure the site with a security solution that sanitizes user‑supplied content to prevent script execution across the page.

Generated by OpenCVE AI on September 23, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Oceanwp
Oceanwp ocean Extra
Wordpress
Wordpress wordpress
Vendors & Products Oceanwp
Oceanwp ocean Extra
Wordpress
Wordpress wordpress

Wed, 23 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Description Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.
Title WordPress Ocean Extra plugin <= 2.6.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Oceanwp Ocean Extra
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-23T18:46:51.988Z

Reserved: 2026-09-22T00:19:50.792Z

Link: CVE-2026-94684

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-23T19:19:50.790

Modified: 2026-09-23T19:39:08.847

Link: CVE-2026-94684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T23:15:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')