WordPress Plugin Vulnerabilities

Oxygen Builder < 4.8.3 - Authenticated (Contributor+) Remote Code Execution

Description

The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is due to the plugin storing custom data in post metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to inject arbitrary PHP code via the WordPress user interface and gain elevated privileges.

Affects Plugins

Fixed in 4.8.3

References

Classification

Type
RCE
OWASP top 10
CWE
CVSS

Miscellaneous

Original Researcher
Francesco Carlucci
Verified
No

Timeline

Publicly Published
2024-05-22 (about 2 years ago)
Added
2024-05-22 (about 2 years ago)
Last Updated
2024-05-23 (about 2 years ago)

Other