What the vulnerability does
01Description
The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.
Explanation of Vulnerability in Simple Terms
02Summary
OoohBoi Steroids for Elementor versions up to 2.1.4 lack proper authorization checks on certain functions. A logged-in user with low privileges can modify content or settings they should not have access to. The vulnerability requires an active WordPress account but no special interaction from other users.
What an attacker can do
03Attacker Capabilities
Modify site content or settings beyond their assigned permission level.
Potential impact on your site
04Site Impact
Unauthorized users can alter pages, posts, or plugin settings, potentially defacing content or breaking site functionality.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
06Disclosure timeline
June 9, 2023
CVE published
April 8, 2026
Record updated