cleantalk
Vulnerabilities and Security Researches

OceanWP, CVE-2025-8944

CVE, Research URL

CVE-2025-8944

Application

OceanWP

Published on
Sep 05, 2025
Research Description
The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.
Affected versions
max 4.1.2.
Status
vulnerable