Stored Cross-Site Scripting Vulnerability in OoohBoi Steroids for Elementor Plugin
CVE-2026-3034
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 March 2026
What is CVE-2026-3034?
The OoohBoi Steroids for Elementor plugin for WordPress suffers from a Stored Cross-Site Scripting vulnerability. This issue arises from the handling of the _ob_spacerat_link, _ob_bbad_link, and _ob_teleporter_link URL parameters, allowing authenticated attackers with Contributor-level access or higher to inject arbitrary web scripts into pages. The injected scripts will execute whenever a user interacts with the compromised elements, potentially leading to unauthorized actions or data exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OoohBoi Steroids for Elementor * <= 2.1.24
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved