Impact
The Ocean Extra plugin for WordPress contains a contributor‑level cross‑site scripting flaw in all releases up to 2.6.1. An attacker who has contributor privileges can inject malicious JavaScript into the plugin’s configuration or content fields, which is then rendered in the front‑end of the site. This type of flaw can be used to steal credentials, deface pages, or serve malware to visitors. The vulnerability is categorized as CWE‑79, which represents a reflected or stored XSS weakness.
Affected Systems
This issue affects the WordPress Ocean Extra plugin provided by OceanWP. All versions 2.6.1 and earlier are vulnerable. Site owners running these versions on a WordPress installation must upgrade the plugin or otherwise mitigate the risk.
Risk and Exploitability
The CVSS score of 6.5 places this as a medium‑severity vulnerability. No EPSS score is available, so the current exploitation probability remains unclear, but the CWE‑79 classification indicates that an attacker who can coerce a contributor can potentially influence page content. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation at present; nevertheless, the potential for unauthorized data disclosure or remote code execution via injected JavaScript warrants prompt remediation.
OpenCVE Enrichment