Vulnerabilities > CVE-2023-0336 - Missing Authorization vulnerability in Ooohboi Steroids for Elementor Project Ooohboi Steroids for Elementor

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE

Summary

The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.

Vulnerable Configurations

Part Description Count
Application
Ooohboi_Steroids_For_Elementor_Project
30

Common Weakness Enumeration (CWE)