CVE-2024-2476

OceanWP <= 3.5.4 - Missing Authorization to Sensitive Information Exposure via Limited Local File Inclusion

The OceanWP theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the load_theme_panel_pane function in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to expose sensitive information such as system/environment data and API keys.


We have discovered 41,993 live websites that are affected by CVE-2024-2476.

Run a Free Instant Scan




Affected Software

Product  OceanWP
Category Wordpress Themes
Vulnerable Domains41,993 live websites (37% of OceanWP install base)
Vulnerable Versions
  • from 0 through 3.5.4
Vulnerable Versions Count169 versions ( 86% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Mar 29, 2024
  • Updated - Apr 8, 2026

Credits

  • Craig Smith (finder)

Website Distribution by Country

Number of websites using CVE-2024-2476
United States8,728 websites



Germany7,236 websites
France3,855 websites
Poland1,637 websites
GB1,486 websites
Italy1,363 websites
Brazil1,331 websites
Russia1,267 websites
Denmark1,032 websites
Netherlands917 websites

Website Distribution by TLD

Number of websites using CVE-2024-2476
.com14,425 websites
.de4,952 websites
.fr1,865 websites
.org1,481 websites
.com.br1,243 websites
.pl1,228 websites
.ru1,048 websites
.it931 websites
.co.uk854 websites
.nl815 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-2476

Top websites that are affected by CVE-2024-2476. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States**,***
***********.com United States**,***
********.com United States**,***
********.**.il Israel**,***
****************.**.il United States**,***
****.**********.com Germany**,***
****.**.za South Africa**,***
*********************.net Germany**,***
*****.net United States***,***
**********.com United States***,***
See full domain list

FAQ

CVE-2024-2476 is Missing Authorization in OceanWP
A total of 41,993 websites have been identified as vulnerable to CVE-2024-2476, based on global website indexing conducted by WebTechSurvey.
The OceanWP is affected by the CVE-2024-2476 vulnerability.
OceanWP versions up to and including 3.5.4 are vulnerable to CVE-2024-2476.