Record summary

CVE-2025-3472 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 2.4.6affected

Nuclei templates

1
ProjectDiscoveryMEDIUMOcean Extra <= 2.4.6 - Unauthenticated Shortcode ExecutionCVSS 6.5

The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to supply arbitrary shortcodes in the content_rech_data parameter that is then executed. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes when WooCommerce is also installed and activated.

Impact

Unauthenticated attackers can execute arbitrary WordPress shortcodes, potentially leading to information disclosure, privilege escalation, or further site compromise depending on available shortcodes.

Remediation

Update Ocean Extra plugin to version 2.4.7 or later.

WeaknessesCWE-94
Authorstheamanrawat
Template tagscvecve2025wordpresswp-pluginocean-extraoceanwpwoocommerceshortcodeunauthvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Shodan: http.html:"oceanwp" http.html:"woocommerce"
FOFA: body="oceanwp" && body="woocommerce"

Source: ProjectDiscovery

References

4