OoohBoi Steroids for Elementor
OoohBoi Steroids for Elementor has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.0, and the most serious one scores 6.4 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Missing Authorization, behind 2 of the records (67%). Other recurring categories include Cross-Site Scripting.
Every one of the 3 issues recorded for OoohBoi Steroids for Elementor has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. OoohBoi Steroids for Elementor is installed on roughly 40,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-3034OoohBoi Steroids for Elementor <= 2.1.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple URL Controls
Read the full analysisVulnerability Records

OoohBoi Steroids for Elementor
Author
Sagar Patel
An awesome set of tools, options and settings that expand Elementor defaults. Instead of creating new Elementor Widgets, these act like an upgrade of existing options or the self-standing panels thing. What is new? Fix for the disappearing ‘Glider’ slider Add/remove/update preview image Export and Import with preview Works with any 3rd party plugin Cross-domain friendly WP Admin integration Bulk-export and bulk-import support Keep template name on export Complete Full Tutorial of OoohBoi Extensions Watch Now
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C