CVE-2023-0336
OoohBoi Steroids for Elementor < 2.1.5 - Subscriber+ Attachment Deletion
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Productos afectados
Unknown · OoohBoi Steroids for Elementor¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →