CVE-2023-1169

The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ooohboi_steroids_for_elementor_project:ooohboi_steroids_for_elementor:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2023-06-09 06:15

Updated : 2023-11-07 04:02


NVD link : CVE-2023-1169

Mitre link : CVE-2023-1169

CVE.ORG link : CVE-2023-1169


JSON object : View

Products Affected

ooohboi_steroids_for_elementor_project

  • ooohboi_steroids_for_elementor
CWE

No CWE.