CVE-2025-3472
Ocean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode Execution
Record summary
CVE-2025-3472 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.
Description
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Ocean ExtraBrowse oceanwp / Ocean ExtraDefault status: unaffected | CVE List | Through 2.4.6 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMOcean Extra <= 2.4.6 - Unauthenticated Shortcode ExecutionCVSS 6.5
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to supply arbitrary shortcodes in the content_rech_data parameter that is then executed. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.
Impact
Unauthenticated attackers can execute arbitrary WordPress shortcodes, potentially leading to information disclosure, privilege escalation, or further site compromise depending on available shortcodes.
Remediation
Update Ocean Extra plugin to version 2.4.7 or later.
Source: ProjectDiscovery