Thème WordPress
Vulnérabilités OceanWP
Cette page rassemble les failles publiées pour OceanWP, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de OceanWP
6 fiches
OceanWP <= 4.1.1 – Missing Authorization to Authenticated (Subscriber+) Settings Update
The OceanWP theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ocean_update_search_box_light_mode AJAX action in all versions up to, and including, 4.1.1. This makes it possible for authenticated attackers,…
*-4.1.1
4.1.2
15/08/2025
OceanWP <= 4.0.9 – 4.1.1 – Cross-Site Request Forgery to Ocean Extra Plugin Installation
The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install…
4.0.9-4.1.1
4.1.2
12/08/2025
Multiple Plugins <= (Various Versions) – Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-3.6.0
3.6.1
02/07/2025
OceanWP <= 4.0.9 – Authenticated (Contributor+) Stored Cross-Site Scripting via Select HTML Tag
The OceanWP theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Select HTML tag in all versions up to, and including, 4.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-4.0.9
4.1.0
18/06/2025
OceanWP <= 3.5.4 – Missing Authorization to Sensitive Information Exposure via Limited Local File Inclusion
The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_theme_panel_pane function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with…
*-3.5.4
3.5.5
28/03/2024
OceanWP <= 3.4.1 – Authenticated (Subscriber+) Local File Inclusion
The OceanWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.4. This allows subscriber-level attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code…
*-3.4.1
3.4.2
27/02/2023
Thèmes également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.