CVE-2026-34903

WordPress Ocean Extra plugin <= 2.5.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in OceanWP Ocean Extra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ocean Extra: from n/a through 2.5.3.


We have discovered 1,121 live websites that are affected by CVE-2026-34903.

Run a Free Instant Scan




Affected Software

Product  Ocean Extra
Category Wordpress Plugins
Vulnerable Domains1,121 live websites (77% of Ocean Extra install base)
Vulnerable Versions
  • from 0 through 2.5.3
Vulnerable Versions Count30 versions ( 94% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Apr 7, 2026
  • Updated - Apr 7, 2026

Credits

  • Nguyen Ba Khanh | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-34903
United States181 websites



Germany234 websites
France117 websites
Italy54 websites
South Africa32 websites
Spain32 websites
Poland31 websites
India30 websites
GB29 websites
Switzerland24 websites

Website Distribution by TLD

Number of websites using CVE-2026-34903
.com345 websites
.de167 websites
.org49 websites
.fr46 websites
.it37 websites
.net26 websites
.pl22 websites
.ch22 websites
.nl22 websites
.com.br22 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-34903

Top websites that are affected by CVE-2026-34903. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.org GB***,***
*******************.org United States*,***,***
*************.com United States*,***,***
*****.***********.dz Algeria*,***,***
*******************.com United States*,***,***
***********.com France*,***,***
***********.com United States*,***,***
*******************.com United States*,***,***
**************.**.uk GB*,***,***
************.net Bulgaria*,***,***
See full domain list

FAQ

CVE-2026-34903 is Missing Authorization in Ocean Extra
A total of 1,121 websites have been identified as vulnerable to CVE-2026-34903, based on global website indexing conducted by WebTechSurvey.
The Ocean Extra is affected by the CVE-2026-34903 vulnerability.
Ocean Extra versions up to and including 2.5.3 are vulnerable to CVE-2026-34903.