{"error":0,"message":null,"data":{"name":"Oxygen","plugin":"oxygen","link":"https:\/\/oxygenbuilder.com\/","latest":null,"closed":null,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"0f9996b02f1fb4e6aab5a7464facd5aed5d2129d8dc93bc236dcd104e6c42456","name":"Oxygen [oxygen] < 4.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-46841","name":"CVE-2022-46841","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-46841","description":"[en] Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Oxygen Builder plugin <=\u00a04.4 versions.","date":"2023-10-03"},{"id":"ef00379e03aff7c40454caf313c3c3382db33032","name":"Oxygen < 4.4 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/oxygen\/oxygen-44-cross-site-request-forgery","description":"The Oxygen plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to 4.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform unauthorized actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2023-07-20"},{"id":"dd0c0d07-db7c-448f-aa76-00e813a50b50","name":"Oxygen Builder &lt; 4.4 - CSRF","link":"https:\/\/wpscan.com\/vulnerability\/dd0c0d07-db7c-448f-aa76-00e813a50b50","description":"The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"865420ae2b3b090779f3f88bcbd9642f241910fcf05dc486fbc4151f8bbd70d7","name":"Oxygen [oxygen] <= 4.9 (unfixed)","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.9","max_operator":"le","unfixed":"1","closed":"0"},"source":[{"id":"CVE-2024-31380","name":"WordPress Oxygen plugin <= 4.9 - Authenticated Remote Code Execution (RCE) vulnerability","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-31380","description":"Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n\/a through 4.9.","date":"2024-04-03"},{"id":"68f1372e29494e6d169e681af382be781d03b70d","name":"WordPress  Oxygen Builder Plugin    <= 4.8.2 is vulnerable to Remote Code Execution (RCE)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/oxygen\/vulnerability\/wordpress-oxygen-plugin-4-8-1-auth-remote-code-execution-rce-vulnerability","description":"The vendor provides no patched version for validation. Minor changes to documentation were made.\nSnicco discovered and reported this Remote Code Execution (RCE) vulnerability in WordPress Oxygen Builder Plugin. This could allow a malicious actor to execute commands on the target website. This can be used to gain backdoor access to then take full control of the website. This vulnerability has not been known to be fixed yet.\nThis vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.\nHave additional information or questions about this entry? Get in touch.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"9.9","severity":"c","exploitable":"3.1","impact":"6.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"9.9","severity":"critical","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"3.1","impact":"6.0"},"cwe":[{"cwe":"CWE-94","name":"Improper Control of Generation of Code ('Code Injection')","description":"The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"8f38e9ce59cbe8eb04ed520b7d45768ad62db3a833af30cda20d48c92b54f695","name":"Oxygen [oxygen] < 6.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"6.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"38ddb8b36334c6b39c71582bcd667b60b6aec2b1","name":"WordPress Oxygen Builder Plugin 6.0-6.1.1 is vulnerable to a medium priority Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/oxygen\/vulnerability\/wordpress-oxygen-plugin-6-0-6-1-1-unauthenticated-broken-access-control-in-design-library-import-vulnerability","description":"<p>WordPress Oxygen Builder Plugin 6.0-6.1.1 is vulnerable to a medium priority Broken Access Control<\/p><p>Software: Oxygen Builder<\/p><p>Link: https:\/\/oxygenbuilder.com<\/p><p>Fixed in version 6.1.2 <\/p><p>Affected Version 6.0-6.1.1<\/p><p>CVE: Unknown<\/p>","date":"2026-08-31"}],"impact":[]},{"uuid":"eea671e777c05b4c1a16b39bff00c5ad8c22df9f12aa9e55095d1013480018c9","name":"Oxygen [oxygen] >= 6.0 - < 6.1.2","description":null,"operator":{"min_version":"6.0","min_operator":"ge","max_version":"6.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"c5a17f00ce86732e6b36114b5accebcb5896dad2","name":"Oxygen 6.0 - 6.1.1 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/oxygen\/oxygen-60-611-missing-authorization","description":"The Oxygen plugin for WordPress is vulnerable to unauthorized access in versions 6.0 through 6.1.1. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2023-07-20"}],"impact":[]}]},"updated":"1788420303"}