{"id":"CVE-2025-8944","title":"The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.","summary":"The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"vendor":"oceanwp","product":"oceanwp","affected":["oceanwp < 4.1.2"],"patched":["oceanwp 4.1.2"],"published":"2025-09-05","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:10:00.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-8944","references":[{"url":"https://wpscan.com/vulnerability/cf77b7f2-525b-4fe8-b612-185a1c18c197/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00232,"epssPercentile":0.12685,"ingestedAt":"2026-09-30T23:29:32.364Z","slug":"CVE-2025-8944","body":"## Overview\n\nThe OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.\n\n## Affected\n\n- `oceanwp < 4.1.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `oceanwp 4.1.2`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}