WordPress Ocean Extra plugin before 1.9.5 contains a cross-site scripting vulnerability. The plugin does not escape generated links which are then used when the OceanWP theme is active.
View the template here CVE-2021-25104.yaml
References:
https://github.com/ARPSyndicate/cvemon