Unrated severityNVD Advisory· Published Sep 5, 2025· Updated Sep 5, 2025
OceanWP < 4.1.2 - Subscriber+ Limited Option Update
CVE-2025-8944
Description
The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.
Affected products
2- OceanWP/OceanWP WordPress themedescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/cf77b7f2-525b-4fe8-b612-185a1c18c197/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.