OoohBoi Steroids for Elementor < 2.1.5 - Subscriber+ Attachment Deletion
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 1.0%
exploitation probability
1.0%top 40% of all CVEs
observed exploitation
nono source reports it
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected products
Unknown · OoohBoi Steroids for Elementor