Ocean Extra
Vendor:
First CVE: Sep 11, 2019 · Active for 6 years
18
Total CVEs
More Total CVEs than 93% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ocean Extra over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2019
6 years ago
Most Recent CVE
Apr 7, 2026
108 days ago
CVE Severity & Scoring
Ocean Extra18 CVEs
78%
17%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (44.4%)
Unknown0 (0.0%)
Required10 (55.6%)
Privileges Required
Low12 (66.7%)
High1 (5.6%)
None5 (27.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3472CRITICAL The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execu | Apr 22, 2025 | 9.8 | 38 | NO | YES |
CVE-2021-25104MEDIUM The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue | Jun 20, 2022 | 6.1 | 31 | NO | YES |
CVE-2019-16250HIGH includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequen | Sep 11, 2019 | 7.5 | 25 | NO | NO |
CVE-2023-49164HIGH Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2. | Dec 19, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-3374HIGH The Ocean Extra WordPress plugin before 2.0.5 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (inte | Oct 31, 2022 | 7.2 | 24 | NO | NO |
CVE-2025-9499MEDIUM The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's oceanwp_library shortcode in all versions up to, and including, 2.4.9 due to insu | Aug 30, 2025 | 6.4 | 22 | NO | NO |
CVE-2026-34903MEDIUM Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through | Apr 7, 2026 | 5.4 | 21 | NO | NO |
CVE-2023-0749MEDIUM The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscr | Mar 13, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-24399MEDIUM Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.2 versions. | Mar 30, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-5531MEDIUM The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions up to, and including, 2.2.8 due to insufficient input saniti | Jun 11, 2024 | 6.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
11.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Ocean Extra
Top CWEs
Versions
No cataloged versions.