Ocean Extra
cpe:2.3:a:oceanwp:ocean_extra:*:*:*:*:wordpress:*:*
- <= 2.4.6
A vulnerability allowing unauthenticated arbitrary shortcode execution has been identified in the Ocean Extra plugin for WordPress, affecting all versions through 2.4.6. The issue arises because the plugin does not properly validate values before executing shortcodes, allowing attackers to exploit this flaw, particularly when WooCommerce is installed and active.
Exploitation of this vulnerability allows for arbitrary shortcode execution, which could lead to various impacts depending on the executed shortcode. In this case, it could be exploited to manipulate WooCommerce cart functionalities.
Users are advised to update the Ocean Extra plugin to version 2.4.7 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.