Arbitrary Shortcode Execution in Ocean Extra Plugin for WordPress
CVE-2025-3472
9.8CRITICAL
What is CVE-2025-3472?
The Ocean Extra plugin for WordPress contains a vulnerability that enables unauthenticated attackers to execute arbitrary shortcodes. This issue arises from improper validation of user input before executing the do_shortcode function. If WooCommerce is installed and activated, exploitability increases, allowing attackers to manipulate site functionality or inject malicious code, posing significant security risks for affected websites.
Affected Version(s)
Ocean Extra * <= 2.4.6