CVE-2024-13362
Ocean Extra
Minimum safe version
2.5.4
Update to 2.5.4 or later to address 34 fixable vulnerabilities
CVE-2026-34903
Ocean Extra <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via oceanwp_library Shortcode
CVE-2025-49068
Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Ocean Extra <= 2.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'ocean_gallery_id'
WordPress Ocean Extra Plugin <= 2.4.6 is vulnerable to Content Injection
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-37489
CVE-2024-5531
CVE-2024-3167
CVE-2024-1277
CVE-2023-49164
Ocean Extra <= 2.2.2 - Cross-Site Request Forgery to Arbitrary Plugin Activation
Ocean Extra < 2.1.3 - Contributor+ Stored XSS
WordPress Ocean Extra Plugin <= 2.1.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2020-36760
CVE-2021-4342
CVE-2023-24399
CVE-2023-0749
Ocean Extra <= 2.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
CVE-2023-23891
Ocean Extra <= 2.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2022-3374
Unauthorised AJAX Calls via Freemius
CVE-2021-25104
WordPress Ocean Extra plugin <= 1.5.8 - Unauthenticated CSS injection vulnerability
WordPress Ocean Extra plugin <= 1.5.8 - Unauthenticated Settings change vulnerability
WordPress Ocean Extra plugin <= 1.6.5 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress Ocean Extra plugin < 1.9.4 - Sensitive Information Disclosure vulnerability
WordPress Ocean Extra plugin < 1.9.4 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2019-16250