Authorization Vulnerability in OoohBoi Steroids for Elementor Plugin
CVE-2023-1169
4.3MEDIUM
What is CVE-2023-1169?
The OoohBoi Steroids for Elementor plugin for WordPress suffers from a missing capability check in the 'file_uploader_callback' function, allowing subscriber-level users to upload image attachments without proper authorization. This vulnerability affects versions up to and including 2.1.4, potentially leading to unauthorized access and exploitation of site functionalities.
Affected Version(s)
OoohBoi Steroids for Elementor * <= 2.1.4