CVE-2025-13307: Ocean Modal Window < 2.3.3 - Editor+ Remote Code Execution via Modal Conditions
The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (editpages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13307?
CVE-2025-13307 is classified as a high-severity vulnerability due to its potential for Remote Code Execution.
How do I fix CVE-2025-13307?
To mitigate CVE-2025-13307, upgrade the Ocean Modal Window WordPress plugin to version 2.3.3 or later.
Which versions of the Ocean Modal Window plugin are affected by CVE-2025-13307?
Versions of the Ocean Modal Window plugin prior to 2.3.3 are affected by CVE-2025-13307.
Who can exploit CVE-2025-13307?
CVE-2025-13307 can be exploited by users with Editor or Administrator capabilities who can set user-controlled conditions for the modals.
What impact does CVE-2025-13307 have on WordPress sites?
CVE-2025-13307 can allow attackers to execute arbitrary code on vulnerable WordPress sites, potentially leading to a full site compromise.