The popular OceanWP theme for WordPress has a security vulnerability that allows attackers to inject malicious code into web pages. This can happen when using the Select HTML tag, and it affects all versions up to 4.0.9. This means that even if a user is logged in with Contributor-level access or higher, they can unknowingly trigger the injected code when visiting a compromised page.