Input validation vulnerability in OceanWP 4.0.9

The popular OceanWP theme for WordPress has a security vulnerability that allows attackers to inject malicious code into web pages. This can happen when using the Select HTML tag, and it affects all versions up to 4.0.9. This means that even if a user is logged in with Contributor-level access or higher, they can unknowingly trigger the injected code when visiting a compromised page.

Detected in:

OceanWP fixed vulnerable versions: >= * <= 4.0.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.