PLUGIN SECURITY
Is Ocean Extra safe?
The ultimate companion for OceanWP. Adds local Google Fonts, mega menus, site templates, and per-page settings for total design authority.
What this plugin does
- Slug:
ocean-extra - Author: oceanwp
- 500000+ active installs
- 66/100 rating (67 reviews on wordpress.org)
- 27881217 all-time downloads
- On WordPress.org since 2016-10-23
meta boxmetaboxmetaboxesoceanwpwidgets
Maintenance status
- Latest known version: 2.5.8
- Last updated: 2026-08-18 2:31pm GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
27 known CVEs on file for Ocean Extra.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2024-13362 | Ocean Extra [ocean-extra] < 2.4.4 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 2.4.4 | 2.4.4 | 2026-04-30 | ✓ fixed in latest |
| CVE-2026-34903 | Ocean Extra [ocean-extra] < 2.5.4 | Missing Authorization | Medium 5.4 | < 2.5.4 | 2.5.4 | 2026-04-07 | ✓ fixed in latest |
| CVE-2025-49068 | Ocean Extra [ocean-extra] < 2.4.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.5 | < 2.4.9 | 2.4.9 | 2025-06-02 | ✓ fixed in latest |
| CVE-2024-37489 | Ocean Extra [ocean-extra] < 2.3.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.3.0 | 2.3.0 | 2024-07-04 | ✓ fixed in latest |
| CVE-2024-5531 | Ocean Extra [ocean-extra] < 2.2.9 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.2.9 | 2.2.9 | 2024-06-10 | ✓ fixed in latest |
| CVE-2024-3167 | Ocean Extra [ocean-extra] < 2.2.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.2.7 | 2.2.7 | 2024-04-08 | ✓ fixed in latest |
| CVE-2024-1277 | Ocean Extra [ocean-extra] < 2.2.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.2.5 | 2.2.5 | 2024-02-16 | ✓ fixed in latest |
| CVE-2023-49164 | Ocean Extra [ocean-extra] < 2.2.3 | Cross-Site Request Forgery (CSRF) | Medium 5.4 | < 2.2.3 | 2.2.3 | 2023-11-28 | ✓ fixed in latest |
+ 30 more known vulnerabilities
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2023-33999 | Ocean Extra [ocean-extra] < 2.1.8 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | High 7.1 | < 2.1.8 | 2.1.8 | 2023-07-18 | ✓ fixed in latest |
| CVE-2021-4342 | Ocean Extra [ocean-extra] < 1.6.6 | — | Unknown | < 1.6.6 | 1.6.6 | 2023-06-07 | ✓ fixed in latest |
| CVE-2023-24399 | Ocean Extra [ocean-extra] < 2.1.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.5 | < 2.1.3 | 2.1.3 | 2023-02-14 | ✓ fixed in latest |
| CVE-2023-0749 | Ocean Extra [ocean-extra] < 2.1.3 | Authorization Bypass Through User-Controlled Key | Medium 6.5 | < 2.1.3 | 2.1.3 | 2023-02-14 | ✓ fixed in latest |
| CVE-2023-23891 | Ocean Extra [ocean-extra] < 2.1.3 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.5 | < 2.1.3 | 2.1.3 | 2023-02-01 | ✓ fixed in latest |
| CVE-2022-3374 | Ocean Extra [ocean-extra] < 2.0.5 | Deserialization of Untrusted Data | High 7.2 | < 2.0.5 | 2.0.5 | 2022-10-10 | ✓ fixed in latest |
| CVE-2021-25104 | Ocean Extra [ocean-extra] < 1.9.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.1 | < 1.9.5 | 1.9.5 | 2022-05-24 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 1.9.4 | Missing Authorization | Medium 6.3 | < 1.9.4 | 1.9.4 | 2022-03-04 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 1.9.4 | — | Unknown | < 1.9.4 | 1.9.4 | 2022-02-28 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 1.9.4 | — | Unknown | < 1.9.4 | 1.9.4 | 2022-02-28 | ✓ fixed in latest |
| CVE-2020-36760 | Ocean Extra [ocean-extra] < 1.6.6 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 1.6.6 | 1.6.6 | 2020-09-26 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 1.6.6 | — | Unknown | < 1.6.6 | 1.6.6 | 2020-09-16 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 1.5.9 | — | Unknown | < 1.5.9 | 1.5.9 | 2019-07-04 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 1.5.9 | — | Unknown | < 1.5.9 | 1.5.9 | 2019-07-04 | ✓ fixed in latest |
| CVE-2019-16250 | Ocean Extra [ocean-extra] < 1.5.9 | Improper Authentication | High 7.5 | < 1.5.9 | 1.5.9 | 2019-07-03 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 2.4.7 | Improper Control of Generation of Code ('Code Injection') | Critical 9.8 | < 2.4.7 | 2.4.7 | 0000-00-00 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 2.4.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.4.7 | 2.4.7 | 0000-00-00 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 2.4.7 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 5.4 | < 2.4.7 | 2.4.7 | 0000-00-00 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 2.5.0 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Medium 6.4 | < 2.5.0 | 2.5.0 | 0000-00-00 | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 1.9.4 | — | Unknown | < 1.9.4 | 1.9.4 | — | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 1.6.6 | — | Unknown | < 1.6.6 | 1.6.6 | — | ✓ fixed in latest |
| — | Ocean Extra [ocean-extra] < 2.1.3 | — | Unknown | < 2.1.3 | 2.1.3 | — | ✓ fixed in latest |
| CVE-2020-36707, CVE-2021-4417, CVE-2020-36752, CVE-2020-36757, CVE-2020-36756, CVE-2020-36761, CVE-2020-36760, CVE-2020-36760 | Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF) | — | Unknown | < 1.6.6 | 1.6.6 | — | ✓ fixed in latest |
| — | Unauthorised AJAX Calls via Freemius | — | Unknown | < 1.9.4 | 1.9.4 | — | ✓ fixed in latest |
| — | Ocean Extra < 2.1.3 - Contributor+ Stored XSS | — | Unknown | < 2.1.3 | 2.1.3 | — | ✓ fixed in latest |
| CVE-2023-49164 | Ocean Extra < 2.2.3 - Cross-Site Request Forgery to Arbitrary Plugin Activation | — | Unknown | < 2.2.3 | 2.2.3 | — | ✓ fixed in latest |
| CVE-2025-3457 | Ocean Extra < 2.4.7 - Contributor+ Stored XSS via Shortcode | — | Unknown | < 2.4.7 | 2.4.7 | — | ✓ fixed in latest |
| CVE-2025-3458 | Ocean Extra < 2.4.7 - Contributor+ Stored XSS via 'ocean_gallery_id' | — | Unknown | < 2.4.7 | 2.4.7 | — | ✓ fixed in latest |
| CVE-2025-3472 | Ocean Extra < 2.4.7 - Unauthenticated Arbitrary Shortcode Execution | — | Unknown | < 2.4.7 | 2.4.7 | — | ✓ fixed in latest |
| CVE-2025-9499 | Ocean Extra < 2.5.0 - Contributor+ Stored XSS | — | Unknown | < 2.5.0 | 2.5.0 | — | ✓ fixed in latest |
How to fix it
Keep Ocean Extra updated — 2.5.8 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Meta Box — 500000+ active installs — 96/100 (165) — max PHP 8.4
- Pure Metafields — 10000+ active installs — 86/100 (6) — max PHP 8.4
- Multi Image Metabox — 7000+ active installs — 98/100 (11)
- CubeWP Framework — 4000+ active installs — 96/100 (12) — max PHP 8.4
- MB Elementor Integration — 2000+ active installs — 74/100 (3)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.