WordPress Ocean Extra plugin before 1.9.5 contains a cross-site scripting vulnerability. The plugin does not escape generated links which are then used when the OceanWP theme is active.
id: CVE-2021-25104
info:
name: WordPress Ocean Extra <1.9.5 - Cross-Site Scripting
author: Akin
...