CVE-2023-0336
OoohBoi Steroids for Elementor < 2.1.5 - Subscriber+ Attachment Deletion
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Produtos afetados
Unknown · OoohBoi Steroids for ElementorQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →