cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forooohboi-steroids-for-elementor ooohboi-steroids-for-elementor

Direction: descending
Jun 07, 2024

OoohBoi Steroids for Elementor # CVE-2023-1169

CVE, Research URL

CVE-2023-1169

Date
Jun 09, 2023
Research Description
The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.
Affected versions
max 2.1.5.
Status
vulnerable

OoohBoi Steroids for Elementor # CVE-2023-0336

CVE, Research URL

CVE-2023-0336

Date
Mar 27, 2023
Research Description
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
Affected versions
max 2.1.5.
Status
vulnerable