CVE-2025-8891 | OceanWP Plugin up to 4.0.9/4.1.1 on WordPress Plugin Installation oceanwp_notice_button_click cross-site request forgery
A vulnerability classified as problematic was found in OceanWP Plugin up to 4.0.9/4.1.1 on WordPress. This vulnerability affects the function oceanwp_notice_button_click of the component Plugin Installation Handler. The manipulation leads to cross-site request forgery.
This vulnerability was named CVE-2025-8891. The attack can be initiated remotely. There is no exploit available.