The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_theme_panel_pane function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose sensitive information such as system/environment data and API keys.
We have discovered 80,888 live websites that are affected by CVE-2024-2476.
Product | ![]() |
Category | Wordpress Themes |
Vulnerable Domains | 80,888 live websites (64.65% of OceanWP install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 240 versions ( 90.91% of all versions) |
![]() | 23,224 websites |
![]() | 14,413 websites |
![]() | 7,626 websites |
![]() | 2,898 websites |
![]() | 2,421 websites |
![]() | 2,156 websites |
![]() | 2,050 websites |
![]() | 1,792 websites |
![]() | 1,581 websites |
![]() | 1,552 websites |
.com | 29,408 websites |
.de | 8,561 websites |
.fr | 3,557 websites |
.org | 2,982 websites |
.com.br | 2,674 websites |
.pl | 2,424 websites |
.co.uk | 1,814 websites |
.ru | 1,798 websites |
.nl | 1,596 websites |
.net | 1,505 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | **,*** | |
***.***.br | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
**********.consulting | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
******.com | ![]() | **,*** | |
********.**.il | ![]() | **,*** | |
****.**********.com | ![]() | **,*** |