CVE-2025-8944: OceanWP < 4.1.2 - Subscriber+ Limited Option Update
The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod setting.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8944?
CVE-2025-8944 is classified with a medium severity level due to its potential impact on the security of the WordPress site.
How do I fix CVE-2025-8944?
To fix CVE-2025-8944, update the OceanWP theme to version 4.1.2 or later.
Who is affected by CVE-2025-8944?
CVE-2025-8944 affects any installation of the OceanWP WordPress theme prior to version 4.1.2.
What type of vulnerability is CVE-2025-8944?
CVE-2025-8944 is a vulnerability related to missing capability checks on AJAX request handlers in the OceanWP theme.
What can attackers do with CVE-2025-8944?
Attackers can exploit CVE-2025-8944 to allow authenticated users, such as subscribers, to modify the darkMode setting without proper permissions.