A vulnerability classified as problematic has been found in Ocean Extra Plugin up to 2.4.9 on WordPress. This issue affects the function
oceanwp_library
of the component Shortcode Handler. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2025-9499. Remote exploitation of the attack is possible. No exploit is available.