Sceawere
Vulnerability Detail
CVE-2026-81929UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in OceanWP Plugins
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- OceanWP
- Product
- Ocean Pro Demos
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter in all versions up to, and including, 1.5.4, and 1.8.0, respectively, due to insufficient authorization, input sanitization, and output escaping in the Popup Builder's save_popup_content AJAX action. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into a published Gutenberg popup that will execute whenever a user accesses a page on which the popup is configured to display. A valid premium license, the Popup Builder module, and at least one published Gutenberg popup configured for display are required.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-09T07:17:18.600Z",
"pubdate": "2026-10-09T07:17:18.600Z",
"executiveSummary": "The Ocean Pro Demos and Ocean eComm Treasure Box WordPress plugins are susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from inadequate input sanitization and output escaping within the Popup Builder module's AJAX handler. The vulnerability allows unauthenticated remote attackers to inject malicious JavaScript payloads into published Gutenberg popups. Once stored, these scripts execute within the context of any user's browser who visits a page where the infected popup is configured to display. Successful exploitation requires the presence of a valid premium license, the activation of the Popup Builder module, and at least one active Gutenberg popup. The impact of this vulnerability is significant, as it facilitates unauthorized script execution, potential session hijacking, administrative credential theft, or the redirection of users to malicious external domains. Given that the attack vector does not require prior authentication, the risk to the site integrity and user data confidentiality is classified as critical.",
"technicalDetails": "The root cause of this vulnerability lies in the improper handling of the 'content' parameter within the 'save_popup_content' AJAX action, located in the Popup Builder functionality of the affected plugins. The application fails to perform sufficient input validation or sanitization on user-supplied data before persisting it to the database, and conversely, fails to implement adequate output encoding when rendering this content within Gutenberg-generated popups. This creates a classic Stored XSS condition.\nExploitation is initiated when an unauthenticated attacker transmits a crafted HTTP POST request targeting the 'save_popup_content' AJAX endpoint. By injecting arbitrary JavaScript tags or malicious event handlers into the 'content' parameter, the attacker can bypass existing security filters due to the lack of server-side sanitization. The malicious payload is subsequently saved as part of the popup configuration in the WordPress database.\nThe attack flow follows a predictable sequence: First, the attacker identifies a WordPress instance running vulnerable versions of Ocean Pro Demos (up to 1.5.4) or Ocean eComm Treasure Box (up to 1.8.0). Second, the attacker interacts with the 'save_popup_content' AJAX action to inject the payload. Third, once a user visits any page on the WordPress site where the compromised popup is configured to render, the browser retrieves the stored malicious string from the database and interprets it as active code rather than plain text.\nBecause the payload executes within the victim's session, the attacker can leverage this access to perform actions on behalf of the victim, including administrative functions if an administrator views the page. The scope of post-exploitation includes, but is not limited to, stealing session cookies, capturing keystrokes, performing unauthorized modifications to site content, or installing additional backdoors via the WordPress plugin/theme editor. The vulnerability is highly potent because it requires no specific user interaction beyond browsing to the infected page, allowing for widespread impact on both site visitors and administrators depending on the visibility settings of the popup."
}