CVE-2025-3472 is a critical vulnerability affecting the Ocean Extra plugin for WordPress, specifically versions up to and including 2.4.6. It allows unauthenticated attackers to execute arbitrary shortcodes due to improper validation, but only when WooCommerce is also installed and active. This flaw carries a CVSS score of 9.8 (Critical), indicating a high potential for complete compromise of confidentiality, integrity, and availability, with a low attack complexity and no user interaction required. While there is no evidence of active exploitation (KEV list inactive) and limited community discussion, a Nuclei template for this vulnerability exists, suggesting potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.4.7CPE matchmatch criteria | cpe:2.3:a:oceanwp:ocean_extra:*:*:*:*:*:wordpress:*:* | ||
>= 0, <= 2.4.6CPE match | cpe:2.3:a:oceanwp:ocean_extra:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.