The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 30 Apr 2025 14:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Oceanwp Oceanwp ocean Extra | |
| CPEs | cpe:2.3:a:oceanwp:ocean_extra:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products | Oceanwp Oceanwp ocean Extra | 
Tue, 22 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 22 Apr 2025 11:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated. | |
| Title | Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution | |
| Weaknesses | CWE-94 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Wordfence
Published: 2025-04-22T11:12:21.180Z
Updated: 2025-04-22T13:23:17.053Z
Reserved: 2025-04-09T15:08:09.560Z
Link: CVE-2025-3472
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-04-22T13:23:06.724Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-04-22T12:15:16.657
Modified: 2025-04-30T14:01:15.660
Link: CVE-2025-3472
 Redhat
                        Redhat
                    No data.