CVE-2025-8944
EUVD-2025-2688105.09.2025, 06:15
The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| oceanwp | oceanwp | 𝑥 < 4.1.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration