๐Ÿ” CVE Alert

CVE-2025-8891

MEDIUM 4.3

OceanWP <= 4.0.9 - 4.1.1 - Cross-Site Request Forgery to Ocean Extra Plugin Installation

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CWE CWE-352
Vendor oceanwp
Product oceanwp
Published Aug 13, 2025
Last Updated Aug 26, 2025
Stay Ahead of the Next One

Get instant alerts for oceanwp oceanwp

Be the first to know when new medium vulnerabilities affecting oceanwp oceanwp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

oceanwp / OceanWP
4.0.9 โ‰ค 4.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/9c6f9a3d-54a6-4405-b42b-37fc8342af96?source=cve themes.trac.wordpress.org: https://themes.trac.wordpress.org/changeset/283264/oceanwp/4.1.2/inc/activation-notice/api.php research.cleantalk.org: https://research.cleantalk.org/cve-2025-8891/

Credits

Dmitrii Ignatyev