WordPress Plugin Vulnerabilities
Oxygen Builder < 4.8.3 - Authenticated (Contributor+) Remote Code Execution
Description
The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is due to the plugin storing custom data in post metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to inject arbitrary PHP code via the WordPress user interface and gain elevated privileges.
Affects Plugins
References
Classification
Type
RCE
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Francesco Carlucci
Verified
No
WPVDB ID
Timeline
Publicly Published
2024-05-22 (about 2 years ago)
Added
2024-05-22 (about 2 years ago)
Last Updated
2024-05-23 (about 2 years ago)