The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Apr 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Oceanwp
Oceanwp ocean Extra |
|
CPEs | cpe:2.3:a:oceanwp:ocean_extra:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Oceanwp
Oceanwp ocean Extra |
Tue, 22 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 22 Apr 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated. | |
Title | Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-04-22T11:12:21.180Z
Updated: 2025-04-22T13:23:17.053Z
Reserved: 2025-04-09T15:08:09.560Z
Link: CVE-2025-3472

Updated: 2025-04-22T13:23:06.724Z

Status : Analyzed
Published: 2025-04-22T12:15:16.657
Modified: 2025-04-30T14:01:15.660
Link: CVE-2025-3472

No data.