CVE-2023-0336

The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ooohboi_steroids_for_elementor_project:ooohboi_steroids_for_elementor:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2023-03-27 16:15

Updated : 2023-11-07 04:00


NVD link : CVE-2023-0336

Mitre link : CVE-2023-0336

CVE.ORG link : CVE-2023-0336


JSON object : View

Products Affected

ooohboi_steroids_for_elementor_project

  • ooohboi_steroids_for_elementor
CWE
CWE-352

Cross-Site Request Forgery (CSRF)

CWE-862

Missing Authorization