CVE-2023-49164
The Ocean Extra plugin for WordPress through version 2.2.2 is susceptible to cross-site request forgery attacks affecting the ajax_required_plugins_activate() function, which fails to properly validate nonces. An unauthenticated attacker could exploit this vulnerability to activate arbitrary plugins by crafting a malicious request, provided an administrator can be socially engineered into clicking a link or visiting a compromised page. The vulnerability was fixed in version 2.2.3.
Based on public CVE data (MITRE/NVD).