Arbitrary Shortcode Execution in Ocean Extra Plugin for WordPress
CVE-2025-3472

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 April 2025

What is CVE-2025-3472?

The Ocean Extra plugin for WordPress contains a vulnerability that enables unauthenticated attackers to execute arbitrary shortcodes. This issue arises from improper validation of user input before executing the do_shortcode function. If WooCommerce is installed and activated, exploitability increases, allowing attackers to manipulate site functionality or inject malicious code, posing significant security risks for affected websites.

Affected Version(s)

Ocean Extra * <= 2.4.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthew Rollings
.
CVE-2025-3472 : Arbitrary Shortcode Execution in Ocean Extra Plugin for WordPress