The Ocean Extra plugin for WordPress has a security vulnerability in versions up to and including 2.4.6. This means that anyone can use a feature that doesn’t check for certain things before running a code. This can allow hackers to run their own codes without needing to log in, especially if WooCommerce is also installed and activated.