Vulnerabilities (CVE)

Filtered by vendor Oceanwp Subscribe
Filtered by product Ocean Extra
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49164 1 Oceanwp 1 Ocean Extra 2023-12-22 N/A 8.8 HIGH
Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.
CVE-2019-16250 1 Oceanwp 1 Ocean Extra 2020-08-24 5.0 MEDIUM 7.5 HIGH
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.