Files
CVEs-PoC/2025/CVE-2025-8944.md
T
2025-09-29 21:09:30 +02:00

759 B

CVE-2025-8944

Description

The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.

POC

Reference

Github

No PoCs found on GitHub currently.