Executive brief
Ocean Product Sharing is a WordPress plugin that allows customers to share products from an online store to social media. A security vulnerability in this plugin allows an attacker with high-level administrative access to inject malicious scripts into the website. If a site visitor or another administrator views the affected page, these scripts could steal session information, redirect users to malicious sites, or deface the web store.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the OceanWP Ocean Product Sharing plugin for WordPress (versions up to and including 2.2.2). The flaw stems from improper neutralization of user-supplied input during web page generation, allowing high-privileged users (such as Shop Managers) to inject arbitrary web scripts. These scripts are stored on the server and executed in the browser of any user who views the impacted page. Exploitation requires network access and a high level of privilege, as well as some user interaction from a victim. The issue is resolved in version 2.2.3.
Affected products
- OceanWP Ocean Product Sharing up to 2.2.2
Timeline
- 2026-06-10: other: Reported by researcher Ananda Dhakal
- 2026-06-18: advisory: Published by Patchstack
- 2026-06-18: patched: Version 2.2.3 released to address the vulnerability