
Cloud Vulnerability DB
A community-led vulnerabilities database
The Oxygen Builder plugin for WordPress contains a Remote Code Execution vulnerability (CVE-2024-4662) affecting all versions up to and including 4.8.2. The vulnerability was discovered and disclosed in May 2024, impacting WordPress installations using the Oxygen Builder plugin (NVD).
The vulnerability stems from the plugin storing custom data in post metadata without an underscore prefix. This implementation flaw allows lower privileged users, such as contributors, to inject arbitrary PHP code through the WordPress user interface. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).
The vulnerability enables attackers with lower-level privileges to execute arbitrary PHP code, potentially leading to elevated privileges and complete system compromise. This poses a significant security risk as it allows unauthorized users to gain administrative access to the WordPress installation (NVD).
The vulnerability can be exploited by users with contributor-level access or higher through the WordPress user interface. The low complexity of exploitation and the lack of required user interaction make this vulnerability particularly concerning (NVD).
Users are strongly advised to update to Oxygen Builder version 4.8.3 or later, which contains the security fix for this vulnerability (Oxygen Builder).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."