Product
The Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress are vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization in the Popup Builder's save_popup_content AJAX action.