Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Ocean Extra
oceanwp
Developer
2.5.1
Latest version
500,000
Installations
Sep 16, 2025
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
20 fixed
7 Mitigation rules
Authenticated (Contributor+) Stored Cross-Site Scripting via oceanwp_library Shortcode vulnerability
<= 2.4.9
Aug 30, 2025
Cross Site Scripting (XSS) vulnerability
<= 2.4.8
Jun 2, 2025
Unauthenticated Arbitrary Shortcode Execution vulnerability
<= 2.4.6
Apr 22, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode vulnerability
<= 2.4.6
Apr 22, 2025
Authenticated Cross Site Scripting (XSS) vulnerability
<= 2.2.9
Jul 4, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting via Flickr Widget vulnerability
<= 2.2.8
Jun 11, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.2.6
Apr 9, 2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.2.4
Feb 19, 2024
CSRF Leading to Arbitrary Plugin Activation vulnerability
<= 2.2.2
Nov 29, 2023
Reflected Cross Site Scripting (XSS) vulnerability
<= 2.1.7
Jul 18, 2023
Cross Site Scripting (XSS) vulnerability
<= 2.1.2
Feb 15, 2023
Subscriber+ Arbitrary Post Content Disclosure vulnerability
< 2.1.3
Feb 15, 2023
Cross Site Scripting (XSS) vulnerability
<= 2.1.1
Feb 2, 2023
Auth. PHP Objection Injection vulnerability
<= 2.0.4
Oct 10, 2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.9.4
May 24, 2022
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
< 1.9.4
Feb 28, 2022
Sensitive Information Disclosure vulnerability
< 1.9.4
Feb 28, 2022
Cross-Site Request Forgery (CSRF) vulnerability
<= 1.6.5
Sep 16, 2020
Unauthenticated Settings change vulnerability
<= 1.5.8
Jul 4, 2019
Unauthenticated CSS injection vulnerability
<= 1.5.8
Jul 4, 2019