PT-2025-17522 · WordPress · Ocean Extra

Matthew Rollings

·

Published

2025-04-22

·

Updated

2026-01-19

·

CVE-2025-3472

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Ocean Extra plugin for WordPress versions up to, and including, 2.4.6
Description The issue is related to arbitrary shortcode execution. It occurs because the software does not properly validate a value before running do shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.
Recommendations For versions up to, and including, 2.4.6, update to a version later than 2.4.6 to resolve the issue. As a temporary workaround, consider disabling the execution of shortcodes from untrusted sources until a patch is available.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-3472

Affected Products

Ocean Extra