Oxygen Builder <= 4.8.3 - Missing Authorization to Authenticated (Subscriber+) Stylesheet Update
medium
The Oxygen Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the oxy_save_css_from_admin AJAX action in all versions up to, and including, 4.8.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update style...
- CVSS:
- 4.3
- Affected:
- up to 4.8.3
- Fixed in:
- 4.9
- Disclosed:
- Aug 26, 2024
CVE-2024-6688 on NVD →
Oxygen Builder <= 4.8.2 - Authenticated (Contributor+) Remote Code Execution
high
The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is due to the plugin storing custom data in post metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to inject ar...
- CVSS:
- 8.8
- Affected:
- up to 4.8.2
- Fixed in:
- 4.8.3
- Disclosed:
- May 22, 2024
CVE-2024-4662 on NVD →
Oxygen Builder <= 4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field
medium
The Oxygen Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom field in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 4.8
- Fixed in:
- 4.8.1
- Disclosed:
- Jan 5, 2024
CVE-2023-6938 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database