The Ocean Extra plugin for WordPress has a security issue where hackers can inject harmful code into the plugin’s oceanwp_library shortcode. This can happen in all versions up to 2.4.9 because the plugin doesn’t properly check and clean the code provided by users. This allows attackers with contributor-level access or higher to add dangerous scripts to pages, which will run whenever a user visits that page.