Stored Cross-Site Scripting in Ocean Pro Demos and Ocean eComm Treasure Box by OceanWP
CVE-2026-81929
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 9 October 2026
What is CVE-2026-81929?
The Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress are susceptible to Stored Cross-Site Scripting (XSS) due to insufficient authorization, input sanitization, and output escaping in the Popup Builder's save_popup_content AJAX action. This vulnerability allows unauthenticated users to exploit the 'content' parameter, injecting arbitrary scripts into published Gutenberg popups. When a user accesses any page featuring the affected popup, the injected scripts will execute, posing a significant security risk. An attacker needs to have a valid premium license and the Popup Builder module activated, along with at least one published Gutenberg popup configured for display.
Affected Version(s)
Ocean eComm Treasure Box 0 <= 1.8.0
Ocean Pro Demos 0 <= 1.5.4