WordPress security by component
Ocean Extra
Plugin description
Ocean Extra is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Apr 07, 2026; the highest CVE/CNA score is 7.5.
Plugin slug:
ocean-extraLatest vulnerability
CVE-2026-34903: Ocean Extra: A security weakness
Ocean Extra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.5.3.
| Safe version |
|
||
|---|---|---|---|
| Apr 07, 2026 |
CVE-2026-34903
Ocean Extra: A security weakness
Ocean Extra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 2.5.3.
|
2.5.4 |
CVE5.4
NVDPending
|
| Aug 30, 2025 |
CVE-2025-9499
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Jun 06, 2025 |
CVE-2025-49068
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 22, 2025 |
CVE-2025-3472
Ocean Extra: A security weakness
Ocean Extra is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD9.8
|
| Apr 22, 2025 |
CVE-2025-3458
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Apr 22, 2025 |
CVE-2025-3457
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Jul 21, 2024 |
CVE-2024-37489
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jun 11, 2024 |
CVE-2024-5531
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Apr 09, 2024 |
CVE-2024-3167
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD6.4
|
| Feb 29, 2024 |
CVE-2024-1277
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Dec 19, 2023 |
CVE-2023-49164
Ocean Extra: Cross-site request forgery
Ocean Extra is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Jul 12, 2023 |
CVE-2020-36760
Ocean Extra: Cross-site request forgery
Ocean Extra is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 06, 2023 |
CVE-2023-23891
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVD5.4
|
| Mar 30, 2023 |
CVE-2023-24399
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.5
NVD5.4
|
| Mar 13, 2023 |
CVE-2023-0749
Ocean Extra: A security weakness
Ocean Extra is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Oct 31, 2022 |
CVE-2022-3374
Ocean Extra: Code execution
Ocean Extra is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Jun 20, 2022 |
CVE-2021-25104
Ocean Extra: Cross-site scripting
Ocean Extra is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Sep 11, 2019 |
CVE-2019-16250
Ocean Extra: A security weakness
Ocean Extra is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|