Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oceanwp

First CVE: Sep 11, 2019Active for: 7 yearsTotal CVEs: 24
29.7
VTI Score
Low

OceanWP is a WordPress theme and plugin vendor whose products target site builders and content creators with design and functionality extensions. The vendor's disclosures cluster around a modestly represented portfolio of web-based components and recur through weakness classes including cross-site scripting, cross-site request forgery, improper authentication, unsafe deserialization, and code injection—a profile consistent with the server-side rendering and plugin architecture of WordPress-based systems. Vulnerabilities affecting this vendor frequently acquire public exploit tooling, reflecting the accessibility of WordPress sites to broad-based scanning and remediation pressure; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Oceanwp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2019
6 years ago
Most Recent CVE
Apr 7, 2026
108 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-3472CRITICAL
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execu
Apr 22, 20259.838NOYES
CVE-2021-25104MEDIUM
The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue
Jun 20, 20226.131NOYES
CVE-2019-16250HIGH
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequen
Sep 11, 20197.525NONO
CVE-2023-49164HIGH
Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.
Dec 19, 20238.824NONO
CVE-2022-3374HIGH
The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (inte
Oct 31, 20227.224NONO
CVE-2023-23700HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OceanWP allows PHP Local File Inclusion.This issue affects OceanWP: from n/a through
May 17, 20247.623NONO
CVE-2022-35730MEDIUM
Cross-Site Request Forgery (CSRF) vulnerability in Oceanwp sticky header plugin <= 1.0.8 on WordPress.
Dec 4, 20226.523NONO
CVE-2025-9499MEDIUM
The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's oceanwp_library shortcode in all versions up to, and including, 2.4.9 due to insu
Aug 30, 20256.422NONO
CVE-2026-34903MEDIUM
Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through
Apr 7, 20265.421NONO
CVE-2023-0749MEDIUM
The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscr
Mar 13, 20236.521NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
79%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (95.8%)
High1 (4.2%)
Unknown0 (0.0%)
User Interaction
None12 (50.0%)
Unknown0 (0.0%)
Required12 (50.0%)
Privileges Required
Low16 (66.7%)
High1 (4.2%)
None7 (29.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
8.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oceanwp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oceanwp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oceanwp's Products

View all 4 CNAs →

Top CWEs