plugin

Ooohboi Steroids For Elementor Vulnerabilities

4 known security issues reported for the Ooohboi Steroids For Elementor WordPress plugin. Most recent disclosed Mar 4, 2026.

4 medium

Running Ooohboi Steroids For Elementor on your site? Check whether your installed version is affected.

Scan your site free

OoohBoi Steroids for Elementor - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls vulnerability

medium

Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls vulnerability

CVSS:
6.5
Affected:
up to 2.1.24
Fixed in:
2.1.25
Disclosed:
Mar 4, 2026

OoohBoi Steroids for Elementor <= 2.1.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls

medium

The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _ob_spacerat_link, _ob_bbad_link, and _ob_teleporter_link URL parameters in all versions up to, and including, 2.1.24. This makes it possible for authenticated attackers, with Contributor-level access and above,...

CVSS:
6.4
Affected:
up to 2.1.24
Fixed in:
2.1.25
Disclosed:
Mar 4, 2026

CVE-2026-3034 on NVD →

OoohBoi Steroids for Elementor <= 2.1.4 - Missing Authorization leading to Authenticated (Subscriber+) Image Upload

medium

The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.

CVSS:
4.3
Affected:
up to 2.1.4
Fixed in:
2.1.5
Disclosed:
Apr 18, 2023

CVE-2023-1169 on NVD →

OoohBoi Steroids for Elementor <= 2.1.3 - Missing Authorization leading to Authenticated (Subscriber+) Attachment Deletion

medium

The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'file_batch_delete_callback' function in versions up to, and including, 2.1.3. This makes it possible for subscriber-level attackers to delete attachments.

CVSS:
4.3
Affected:
up to 2.1.3
Fixed in:
2.1.5
Disclosed:
Feb 28, 2023

CVE-2023-0336 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database