CVE-2023-0749
The Ocean Extra plugin for WordPress through version 2.1.2 contains a flaw in the oceanwp_library shortcode that fails to check whether a post has been published before displaying its content. Attackers with subscriber-level access or higher can exploit this vulnerability to view private or draft posts that should not be accessible to them. The issue allows unauthorized disclosure of sensitive post content that was intended to be restricted. This vulnerability was patched in version 2.1.3.
Based on public CVE data (MITRE/NVD).