Stored Cross-Site Scripting in Ocean Pro Demos and Ocean eComm Treasure Box by OceanWP
CVE-2026-81929

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 October 2026

What is CVE-2026-81929?

The Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress are susceptible to Stored Cross-Site Scripting (XSS) due to insufficient authorization, input sanitization, and output escaping in the Popup Builder's save_popup_content AJAX action. This vulnerability allows unauthenticated users to exploit the 'content' parameter, injecting arbitrary scripts into published Gutenberg popups. When a user accesses any page featuring the affected popup, the injected scripts will execute, posing a significant security risk. An attacker needs to have a valid premium license and the Popup Builder module activated, along with at least one published Gutenberg popup configured for display.

Affected Version(s)

Ocean eComm Treasure Box 0 <= 1.8.0

Ocean Pro Demos 0 <= 1.5.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Thomas
Wordfence Argus
.