---
id: CVE-2025-8944
title: >-
  The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due
  to a missing capability check on one of its AJAX request handler, allowing any
  authenticated users, such as subscriber to update the darkMod` setting.
summary: >-
  The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due
  to a missing capability check on one of its AJAX request handler, allowing any
  authenticated users, such as subscriber to update the darkMod` setting.
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
vendor: oceanwp
product: oceanwp
affected:
  - oceanwp < 4.1.2
patched:
  - oceanwp 4.1.2
published: '2025-09-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8944'
references:
  - url: 'https://wpscan.com/vulnerability/cf77b7f2-525b-4fe8-b612-185a1c18c197/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00232
epssPercentile: 0.12685
ingestedAt: '2026-09-30T23:29:32.364Z'
---

## Overview

The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of its AJAX request handler, allowing any authenticated users, such as subscriber to update the darkMod` setting.

## Affected

- `oceanwp < 4.1.2`

## Remediation

Upgrade past the affected range:

- `oceanwp 4.1.2`
