OceanWP
OceanWP has 6 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 6 are fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 4 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (33%). Other recurring categories include Missing Authorization, Cross-Site Request Forgery (CSRF).
Every one of the 6 issues recorded for OceanWP has a vendor fix available, so running the current release closes all known holes.
5 independent researchers contributed these findings, most of them (2) reported by Webbernaut. OceanWP is installed on roughly 500,000 WordPress sites, so each unpatched flaw has a wide blast radius.
CVE-2023-23700OceanWP <= 3.4.1 - Authenticated (Subscriber+) Local File Inclusion
Read the full analysisVulnerability Records

OceanWP
Author
oceanwp
OceanWP is the perfect theme for your project. Lightweight and highly extendable, it will enable you to create almost any type of website such a blog, portfolio, business website and WooCommerce storefront with a beautiful & professional design. Very fast, responsive, RTL & translation ready, best SEO practices, unique WooCommerce features to increase conversion and much more. You can even edit the settings on tablet & mobile so your site looks good on every device. Work with the most popular page builders as Elementor, Beaver Builder, Brizy, Visual Composer, Divi, SiteOrigin, etc... Developers will love his extensible codebase making it a joy to customize and extend. Best friend of Elementor & WooCommerce. Looking for a Multi-Purpose theme? Look no further! Check the demos to realize that it's the only theme you will ever need: https://oceanwp.org/demos/
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C