CVE-2023-0336

CVE-2023-0336: OoohBoi Steroids for Elementor < 2.1.5 - Subscriber+ Attachment Deletion

Vendor Unknown
Product OoohBoi Steroids for Elementor
Published March 27, 2023
Last update February 19, 2025

CVSS base score

What the vulnerability does

01Description

The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.

Key dates

02Disclosure timeline

March 27, 2023 CVE published
February 19, 2025 Record updated