CVE 6.5 MEDIUM

Ocean Modal Window < 2.3.3 - Editor+ Remote Code Execution via Modal Conditions_CVE-2025-13307

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.

Basic Information

ID CVE-2025-13307
Source WPScan
Published Dec 19, 2025 at 06:00
Modified Dec 19, 2025 at 15:42

Affected Product

Vendor Unknown
Product Ocean Modal Window
Affected Versions Unknown Ocean Modal Window 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.