Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-25104 1 Oceanwp 1 Ocean Extra 2024-11-21 6.1 Medium
The Ocean Extra WordPress plugin before 1.9.5 does not escape generated links which are then used when the OceanWP is active, leading to a Reflected Cross-Site Scripting issue
CVE-2019-16250 1 Oceanwp 1 Ocean Extra 2024-11-21 7.5 High
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.