Ocean Extra

Vulnerabilities 34Slug ocean-extraLatest version 2.5.5WordPress.org →

Minimum safe version

2.5.4

Update to 2.5.4 or later to address 34 fixable vulnerabilities

Latest available2.5.5
Medium 6.4
2025-08-30< 2.5.0

Ocean Extra <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via oceanwp_library Shortcode

Medium 6.4
2025-04-22< 2.4.7

Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Medium 6.4
2025-04-22< 2.4.7

Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ocean_gallery_id'

Medium 6.5
2025-04-22< 2.4.7

WordPress Ocean Extra Plugin <= 2.4.6 is vulnerable to Content Injection

Medium 6.3
2024-10-16< 1.9.4

Freemius SDK <= 2.4.2 - Missing Authorization Checks

N/A
2023-11-28< 2.2.3

Ocean Extra <= 2.2.2 - Cross-Site Request Forgery to Arbitrary Plugin Activation

N/A
< 2.1.3

Ocean Extra &lt; 2.1.3 - Contributor+ Stored XSS

N/A
2023-07-18< 2.1.8

WordPress Ocean Extra Plugin <= 2.1.7 is vulnerable to Cross Site Scripting (XSS)

N/A
2023-06-07< 1.6.6

CVE-2021-4342

N/A
2023-02-14< 2.1.3

Ocean Extra <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

N/A
2023-02-01< 2.1.2

Ocean Extra <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

N/A
< 1.6.6

Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass

N/A
2022-03-04< 1.9.4

Freemius SDK <= 2.4.2 - Missing Authorization Checks

N/A
< 1.9.4

Unauthorised AJAX Calls via Freemius

N/A
2019-07-04< 1.5.9

WordPress Ocean Extra plugin <= 1.5.8 - Unauthenticated CSS injection vulnerability

N/A
2019-07-04< 1.5.9

WordPress Ocean Extra plugin <= 1.5.8 - Unauthenticated Settings change vulnerability

N/A
2020-09-16< 1.6.6

WordPress Ocean Extra plugin <= 1.6.5 - Cross-Site Request Forgery (CSRF) vulnerability

N/A
2022-02-28< 1.9.4

WordPress Ocean Extra plugin < 1.9.4 - Sensitive Information Disclosure vulnerability

N/A
2022-02-28< 1.9.4

WordPress Ocean Extra plugin < 1.9.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability