Themes Vulnerabilities

OceanWP < 4.1.2 - Subscriber+ Limited Option Update

Description

The theme is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.

Proof of Concept

Affects Themes

Fixed in 4.1.2

References

Classification

Type
INCORRECT AUTHORISATION
CWE

Miscellaneous

Original Researcher
Hamit Cibo
Submitter
Hamit Cibo
Submitter website
Verified
Yes

Timeline

Publicly Published
2025-08-15 (about 4 months ago)
Added
2025-08-15 (about 4 months ago)
Last Updated
2025-08-15 (about 4 months ago)

Other