The Ocean Extra plugin for WordPress has a security vulnerability that allows attackers to inject harmful code into website pages. This can happen when someone with contributor-level access or higher uses the plugin’s ‘oceanwp_icon’ feature, and the plugin does not properly protect against this type of attack.