The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/cf77b7f2-525b-4fe8-b612-185a1c18c197/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-09-05 06:15
Updated : 2026-01-20 21:38
NVD link : CVE-2025-8944
Mitre link : CVE-2025-8944
CVE.ORG link : CVE-2025-8944
JSON object : View
Products Affected
oceanwp
- oceanwp
CWE
CWE-862
Missing Authorization
