Loading vulnerability details…
CVSS v3.1
6.5
EPSS
1.00%
Published
Mar 27, 2023
Modified
Feb 19, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NWeaknesses (CWE)
Affected Products (1)
References (2)