CVE-2026-94684: WordPress Ocean Extra plugin <= 2.6.1 - Cross Site Scripting (XSS) vulnerability
Published Sep 23, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.
Affected Software
1 affected component
Oceanwp Ocean Extra<=2.6.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Ocean Extra pluginto a version that resolves this vulnerability.Fixed in 2.6.2
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is described as contributor XSS, so an attacker needs Contributor-level access to a WordPress site using an affected Ocean Extra version.
2
Does exploitation require someone else to interact with attacker-controlled content?
Yes. The supplied CVSS vector includes UI:R, indicating that user interaction is required for exploitation.
3
What is the potential impact if the XSS is exploited?
The CVSS metrics indicate low-impact effects on confidentiality, integrity, and availability, with scope changed. Successful exploitation could affect a security context beyond the vulnerable component.