The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.
Metrics
Affected Vendors & Products
References
History
Fri, 19 Dec 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution. | |
| Title | Ocean Modal Window < 2.3.3 - Editor+ Remote Code Execution via Modal Conditions | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published: 2025-12-19T06:00:06.104Z
Updated: 2025-12-19T06:00:06.104Z
Reserved: 2025-11-17T14:26:04.115Z
Link: CVE-2025-13307
No data.
Status : Received
Published: 2025-12-19T06:15:50.837
Modified: 2025-12-19T06:15:50.837
Link: CVE-2025-13307
No data.