WordPress Ocean Extra plugin before 1.9.5 contains a cross-site scripting vulnerability. The plugin does not escape generated links which are then used when the OceanWP theme is active.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view