CVE-2025-8891 | OceanWP Plugin up to 4.0.9/4.1.1 on WordPress Plugin Installation oceanwp_notice_button_click cross-site request forgery
A vulnerability, which was classified as problematic, has been found in OceanWP Plugin up to 4.0.9/4.1.1 on WordPress. This affects the function oceanwp_notice_button_click of the component Plugin Installation Handler. Performing manipulation results in cross-site request forgery.
This vulnerability is identified as CVE-2025-8891. The attack can be initiated remotely. There is not any exploit available.