Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-8891

Опубликовано: 13 авг. 2025
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:oceanwp:oceanwp:*:*:*:*:*:wordpress:*:*
Версия от 4.0.9 (включая) до 4.1.1 (включая)

EPSS

Процентиль: 2%
0.00015
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.3
github
6 месяцев назад

The OceanWP theme for WordPress is vulnerable to Cross-Site Request Forgery in versions 4.0.9 to 4.1.1. This is due to missing or incorrect nonce validation on the oceanwp_notice_button_click() function. This makes it possible for unauthenticated attackers to install the Ocean Extra plugin via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

EPSS

Процентиль: 2%
0.00015
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-352