CVE-2023-0336

The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ooohboi_steroids_for_elementor_project:ooohboi_steroids_for_elementor:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:36

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/ac74df9a-6fbf-4411-a501-97eba1ad1895 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/ac74df9a-6fbf-4411-a501-97eba1ad1895 - Exploit, Third Party Advisory

Information

Published : 2023-03-27 16:15

Updated : 2024-11-21 07:36


NVD link : CVE-2023-0336

Mitre link : CVE-2023-0336

CVE.ORG link : CVE-2023-0336


JSON object : View

Products Affected

ooohboi_steroids_for_elementor_project

  • ooohboi_steroids_for_elementor
CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization