WordPress Plugin Vulnerabilities

OoohBoi Steroids for Elementor < 2.1.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls

Description

The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _ob_spacerat_link, _ob_bbad_link, and _ob_teleporter_link URL parameters in all versions up to, and including, 2.1.24. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user clicks on the injected element.

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Osvaldo Noe Gonzalez Del Rio (Os)
Verified
No

Timeline

Publicly Published
2026-03-04 (about 2 months ago)
Added
2026-03-04 (about 2 months ago)
Last Updated
2026-03-05 (about 2 months ago)

Other