The Ocean Extra plugin for WordPress has a security vulnerability that could allow malicious attackers with contributor level permissions or higher to inject harmful code into pages. This code will be executed whenever a user accesses the page. This vulnerability affects versions of the plugin up to and including 2.1.2