The OceanWP theme for WordPress has a security issue that allows unauthorized users to access sensitive data. This is because the theme does not have a check in place to prevent this type of access. This vulnerability affects all versions of the theme up to version 3.5.4. As a result, attackers who have at least subscriber-level access can view important information like system and environment data, as well as API keys.