Pricing
Case studies
Login
Start trial
Ocean Extra
oceanwp
Developer
2.5.5
Latest version
500,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
21 patched
7 Mitigation rules
Authenticated (Contributor+) Stored Cross-Site Scripting via 'ocean_gallery_id' vulnerability
<= 2.4.6
31/12/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via oceanwp_library Shortcode vulnerability
<= 2.4.9
30/08/2025
Cross Site Scripting (XSS) vulnerability
<= 2.4.8
02/06/2025
Unauthenticated Arbitrary Shortcode Execution vulnerability
<= 2.4.6
22/04/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 2.4.6
22/04/2025
Authenticated Cross Site Scripting (XSS) vulnerability
<= 2.2.9
04/07/2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Flickr Widget vulnerability
<= 2.2.8
11/06/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.2.6
09/04/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.2.4
19/02/2024
CSRF Leading to Arbitrary Plugin Activation vulnerability
<= 2.2.2
29/11/2023
Reflected Cross Site Scripting (XSS) vulnerability
<= 2.1.7
18/07/2023
Cross Site Scripting (XSS) vulnerability
<= 2.1.2
15/02/2023
Subscriber+ Arbitrary Post Content Disclosure vulnerability
< 2.1.3
15/02/2023
Cross Site Scripting (XSS) vulnerability
<= 2.1.1
02/02/2023
Auth. PHP Objection Injection vulnerability
<= 2.0.4
10/10/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.9.4
24/05/2022
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
< 1.9.4
28/02/2022
Sensitive Information Disclosure vulnerability
< 1.9.4
28/02/2022
Cross-Site Request Forgery (CSRF) vulnerability
<= 1.6.5
16/09/2020
Unauthenticated Settings change vulnerability
<= 1.5.8
04/07/2019
Unauthenticated CSS injection vulnerability
<= 1.5.8
04/07/2019