CVE · Medium

CVE-2020-36760 — Ocean Extra [ocean-extra] < 1.6.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-36760 Ocean Extra [ocean-extra] < 1.6.6 Cross-Site Request Forgery (CSRF) Medium 4.3 < 1.6.6 1.6.6 2020-09-26

CVE-2020-36760

The Ocean Extra plugin for WordPress through version 1.6.5 contains a Cross-Site Request Forgery vulnerability because the add_core_extensions_bundle_validation() function lacks proper nonce verification. Attackers without authentication can exploit this to validate extension bundles by crafting malicious requests, provided they can convince an administrator to click a link or perform a similar action. The vulnerability was fixed in version 1.6.6.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.