{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aoceanwpocean_ecomm_treasure_boxwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:oceanwp:ocean_pro_demos:*:*:*:*:*:wordpress:*:*","cpe:2.3:a:oceanwp:ocean_ecomm_treasure_box:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-81929"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ocean Pro Demos (\u003c= 1.5.4)","Ocean eComm Treasure Box (\u003c= 1.8.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","wordpress","xss"],"_cs_type":"advisory","_cs_vendors":["OceanWP"],"content_html":"\u003cp\u003eThe Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress contain a critical vulnerability in the Popup Builder module. Specifically, the 'save_popup_content' AJAX action lacks sufficient authorization, input sanitization, and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into Gutenberg popups.\u003c/p\u003e\n\u003cp\u003eThe vulnerability, tracked as CVE-2026-81929, affects Ocean Pro Demos versions up to and including 1.5.4, and Ocean eComm Treasure Box versions up to and including 1.8.0. Successful exploitation occurs when a victim accesses a page where a malicious popup is configured to display, leading to script execution within the user's browser session. Prerequisites for this attack include a valid premium license, the activation of the Popup Builder module, and at least one published Gutenberg popup. This flaw poses a significant risk as it allows for unauthorized script execution in the context of user sessions, potentially leading to session hijacking or administrative credential theft.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform Stored XSS against users visiting the site. This can result in session hijacking, unauthorized actions performed on behalf of legitimate users, or the redirection of site traffic to malicious domains. The vulnerability impacts any WordPress installation utilizing the vulnerable versions of these plugins with the specified module and popup configuration enabled.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams managing WordPress environments:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and audit all WordPress installations utilizing 'Ocean Pro Demos' and 'Ocean eComm Treasure Box'.\u003c/li\u003e\n\u003cli\u003eVerify the plugin versions in use against the vulnerable ranges: Ocean Pro Demos \u0026lt;= 1.5.4 and Ocean eComm Treasure Box \u0026lt;= 1.8.0.\u003c/li\u003e\n\u003cli\u003eUpgrade both plugins to versions released after 1.5.4 and 1.8.0 respectively, as soon as security patches are available from the vendor.\u003c/li\u003e\n\u003cli\u003eDisable the 'Popup Builder' module if it is not required for site functionality to eliminate the attack surface for this CVE.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T08:04:10Z","date_published":"2026-10-09T08:04:10Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-81929/","summary":"The Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress are vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization in the Popup Builder's save_popup_content AJAX action.","title":"Stored XSS in Ocean Pro Demos and Ocean eComm Treasure Box WordPress Plugins","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-81929/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:oceanwp:ocean_ecomm_treasure_box:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}