CVE-2025-8944

MEDIUM

OceanWP < 4.1.2 - Authenticated Missing Authorization via AJAX Request Handler

Title source: llm
STIX 2.1

Description

The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/cf77b7f2-525b-4fe8-b612-185a1c18c197/

Scores

CVSS v3 4.3
EPSS 0.0021
EPSS Percentile 11.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
oceanwp/oceanwp < 4.1.2
Published Sep 05, 2025
Tracked Since Feb 18, 2026