<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ocean EComm Treasure Box (&lt;= 1.8.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ocean-ecomm-treasure-box--1.8.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 08:04:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ocean-ecomm-treasure-box--1.8.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Ocean Pro Demos and Ocean eComm Treasure Box WordPress Plugins</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-81929/</link><pubDate>Fri, 09 Oct 2026 08:04:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-81929/</guid><description>The Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress are vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization in the Popup Builder's save_popup_content AJAX action.</description><content:encoded><![CDATA[<p>The Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress contain a critical vulnerability in the Popup Builder module. Specifically, the 'save_popup_content' AJAX action lacks sufficient authorization, input sanitization, and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into Gutenberg popups.</p>
<p>The vulnerability, tracked as CVE-2026-81929, affects Ocean Pro Demos versions up to and including 1.5.4, and Ocean eComm Treasure Box versions up to and including 1.8.0. Successful exploitation occurs when a victim accesses a page where a malicious popup is configured to display, leading to script execution within the user's browser session. Prerequisites for this attack include a valid premium license, the activation of the Popup Builder module, and at least one published Gutenberg popup. This flaw poses a significant risk as it allows for unauthorized script execution in the context of user sessions, potentially leading to session hijacking or administrative credential theft.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to perform Stored XSS against users visiting the site. This can result in session hijacking, unauthorized actions performed on behalf of legitimate users, or the redirection of site traffic to malicious domains. The vulnerability impacts any WordPress installation utilizing the vulnerable versions of these plugins with the specified module and popup configuration enabled.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams managing WordPress environments:</p>
<ul>
<li>Identify and audit all WordPress installations utilizing 'Ocean Pro Demos' and 'Ocean eComm Treasure Box'.</li>
<li>Verify the plugin versions in use against the vulnerable ranges: Ocean Pro Demos &lt;= 1.5.4 and Ocean eComm Treasure Box &lt;= 1.8.0.</li>
<li>Upgrade both plugins to versions released after 1.5.4 and 1.8.0 respectively, as soon as security patches are available from the vendor.</li>
<li>Disable the 'Popup Builder' module if it is not required for site functionality to eliminate the attack surface for this CVE.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>wordpress</category><category>xss</category></item></channel></rss>