The Ocean Extra plugin for WordPress has a security issue called Stored Cross-Site Scripting. This happens when the Flickr widget is used in versions 2.2.8 and below because it doesn’t properly clean or protect the information provided by users. This means that attackers who have contributor-level access or higher can insert dangerous web scripts into pages that will run when someone visits the page.