N/A
2025-09-05< 4.1.2
OceanWP <= 4.1.1 - Missing Authorization to Authenticated (Subscriber+) Settings Update
Minimum safe version
4.1.2
Update to 4.1.2 or later to address 6 fixable vulnerabilities
OceanWP <= 4.1.1 - Missing Authorization to Authenticated (Subscriber+) Settings Update
OceanWP <= 4.0.9 - 4.1.1 - Cross-Site Request Forgery to Ocean Extra Plugin Installation
Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
WordPress OceanWP Theme <= 4.0.9 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-2476
CVE-2023-23700