Access violation vulnerability in OoohBoi Steroids for Elementor 2.1.4

The OoohBoi Steroids for Elementor plugin for WordPress has a security issue that affects all versions up to 2.1.4. An attacker with a subscriber-level account (the lowest level of access) can upload images to the website without being authorized to do so. This is because the plugin does not check if the user has the correct capabilities when using the ‘file_uploader_callback’ function.

Detected in:

OoohBoi Steroids for Elementor fixed vulnerable versions: >= * <= 2.1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.