CVE-2020-36760
The Ocean Extra plugin for WordPress through version 1.6.5 contains a Cross-Site Request Forgery vulnerability because the add_core_extensions_bundle_validation() function lacks proper nonce verification. Attackers without authentication can exploit this to validate extension bundles by crafting malicious requests, provided they can convince an administrator to click a link or perform a similar action. The vulnerability was fixed in version 1.6.6.
Based on public CVE data (MITRE/NVD).