CVE-2024-4662
Oxygen Builder <= 4.8.2 - Authenticated (Contributor+) Remote Code Execution
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is due to the plugin storing custom data in post metadata without an underscore prefix. This makes it possible for lower privileged users, such as contributors, to inject arbitrary PHP code via the WordPress user interface and gain elevated privileges.
| CWE | CWE-94 |
| Vendor | oxygen builder |
| Product | oxygen builder |
| Published | May 23, 2024 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for oxygen builder oxygen builder
Be the first to know when new high vulnerabilities affecting oxygen builder oxygen builder are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Oxygen Builder / Oxygen Builder
0 โค 4.8.2
References
Credits
Francesco Carlucci