OceanWP is a WordPress theme and plugin vendor whose products target site builders and content creators with design and functionality extensions. The vendor's disclosures cluster around a modestly represented portfolio of web-based components and recur through weakness classes including cross-site scripting, cross-site request forgery, improper authentication, unsafe deserialization, and code injection—a profile consistent with the server-side rendering and plugin architecture of WordPress-based systems. Vulnerabilities affecting this vendor frequently acquire public exploit tooling, reflecting the accessibility of WordPress sites to broad-based scanning and remediation pressure; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oceanwp over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3472CRITICAL The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execu | Apr 22, 2025 | 9.8 | 38 | NO | YES |
CVE-2021-25104MEDIUM The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue | Jun 20, 2022 | 6.1 | 31 | NO | YES |
CVE-2019-16250HIGH includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequen | Sep 11, 2019 | 7.5 | 25 | NO | NO |
CVE-2023-49164HIGH Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2. | Dec 19, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-3374HIGH The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (inte | Oct 31, 2022 | 7.2 | 24 | NO | NO |
CVE-2023-23700HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OceanWP allows PHP Local File Inclusion.This issue affects OceanWP: from n/a through | May 17, 2024 | 7.6 | 23 | NO | NO |
CVE-2022-35730MEDIUM Cross-Site Request Forgery (CSRF) vulnerability in Oceanwp sticky header plugin <= 1.0.8 on WordPress. | Dec 4, 2022 | 6.5 | 23 | NO | NO |
CVE-2025-9499MEDIUM The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's oceanwp_library shortcode in all versions up to, and including, 2.4.9 due to insu | Aug 30, 2025 | 6.4 | 22 | NO | NO |
CVE-2026-34903MEDIUM Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through | Apr 7, 2026 | 5.4 | 21 | NO | NO |
CVE-2023-0749MEDIUM The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscr | Mar 13, 2023 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oceanwp.
Media articles that mention a CVE ID that affects a product developed by Oceanwp — matched by CVE ID, not by vendor name.