PoC Index

CVE-2025-13307

HIGH 7.2EPSS 0.6%

The Ocean Modal Window WordPress plugin before 2.3.3 is vulnerable to Remote Code Execution via the modal display logic. These modals can be displayed under user-controlled conditions that Editors and Administrators can set (edit_pages capability). The conditions are then executed as part of an eval statement executed on every site page. This leads to remote code execution.

CVSS v3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.57% chance of exploitation in the next 30 days, 45th percentile
Published
2025-12-19

Proof-of-concept exploits (1)

References

Related