CVE-2026-3034
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-3034 is a Stored Cross-Site Scripting (XSS) vulnerability in the OoohBoi Steroids for Elementor WordPress plugin. It affects all versions up to and including 2.1.24, allowing authenticated attackers with Contributor-level access or above to inject arbitrary web scripts via the _ob_spacerat_link, _ob_bbad_link, and _ob_teleporter_link URL parameters. The injected scripts execute in the context of any user who clicks on the affected element. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The root cause is insufficient sanitization and validation of URL parameters (_ob_spacerat_link, _ob_bbad_link, _ob_teleporter_link) processed by the plugin's JavaScript files (spacerat.js and ooohboi-steroids.js). An attacker with at least Contributor-level WordPress access can craft a malicious URL value that is stored in the database and later rendered unsanitized in page output, triggering script execution when a visitor interacts with the injected element (Wordfence, WordPress Plugin Trac).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of site visitors or administrators who interact with the compromised page element. This can lead to session cookie theft, credential harvesting, defacement of page content, or redirection to malicious sites. While availability is not directly impacted, the confidentiality and integrity of user sessions and site content are at risk. The changed scope (S:C) indicates the impact can extend beyond the plugin itself to the broader WordPress site and its users (Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.032%, indicating a low probability of exploitation in the near term. The vulnerability requires authenticated access at the Contributor level or above, which limits the attack surface compared to unauthenticated vulnerabilities. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the OoohBoi Steroids for Elementor plugin (version ≤ 2.1.24) via WPScan, Shodan, or manual inspection of page source for plugin-specific assets.
  2. Obtain Contributor Access: Register or compromise a Contributor-level (or higher) WordPress account on the target site.
  3. Create or Edit a Page/Post: Using the Elementor editor, add a widget or element that utilizes one of the vulnerable parameters (_ob_spacerat_link, _ob_bbad_link, or _ob_teleporter_link).
  4. Inject Malicious Payload: Set the URL parameter value to a JavaScript payload, e.g., javascript:alert(document.cookie) or a more sophisticated payload that exfiltrates session cookies to an attacker-controlled server.
  5. Publish Content: Save and publish the page. The malicious script is now stored in the WordPress database.
  6. Trigger Execution: When a site visitor or administrator clicks on the injected element, the stored XSS payload executes in their browser, enabling session hijacking, credential theft, or further attacks (Wordfence, WordPress Plugin Trac).

Indicators of compromise

  • Database/Content: WordPress post or page content containing JavaScript payloads (e.g., <script>, javascript:, onerror=, onmouseover=) within _ob_spacerat_link, _ob_bbad_link, or _ob_teleporter_link meta fields.
  • Logs: WordPress access logs showing authenticated POST requests to wp-admin/post.php or REST API endpoints with suspicious URL-encoded JavaScript in widget/element parameters.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after page interaction, potentially carrying cookie or session data in query parameters.
  • File System: No direct file system artifacts expected for stored XSS; however, review Elementor-saved templates and post meta in the WordPress database for unexpected script content.

Mitigation and workarounds

Site administrators should update the OoohBoi Steroids for Elementor plugin to a version beyond 2.1.24 that includes a fix for this vulnerability. Check the plugin's changelog for the patched release. As an interim measure, restrict Contributor-level user registrations or limit who can create/edit content using Elementor widgets. Web Application Firewalls (WAFs) with XSS filtering rules can provide additional defense-in-depth (Wordfence, WordPress Plugin Page).

Community reactions

The vulnerability was assigned and disclosed by Wordfence, a leading WordPress security firm, and published on March 5, 2026. It was subsequently indexed by ENISA's EUVD (EUVD-2026-9525) and referenced by Red Hat's CVE database. No significant independent researcher commentary or broad media coverage has been identified beyond standard vulnerability aggregator listings (Wordfence, Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-17087HIGH7.5
  • wp-travel-engine
NoYesAug 16, 2026
CVE-2026-2497HIGH7.2
  • gallery-plugin
NoYesAug 16, 2026
CVE-2026-17608MEDIUM6.5
  • wp-compress-image-optimizer
NoYesAug 16, 2026
CVE-2026-2357MEDIUM6.4
  • bold-page-builder
NoYesAug 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management