Stored Cross-Site Scripting Vulnerability in OceanWP Theme for WordPress
CVE-2025-5524
4.9MEDIUM
What is CVE-2025-5524?
The OceanWP theme for WordPress contains a flaw that allows for Stored Cross-Site Scripting due to inadequate input validation and output sanitization. This vulnerability affects all versions up to and including 4.0.9, where authenticated users with Contributor-level permissions can exploit the Select HTML tag to embed malicious web scripts. These scripts are executed automatically when users visit the compromised pages, posing a significant risk to site security and user data.
Affected Version(s)
OceanWP * <= 4.0.9