ZeroHour

CVE-2023-2329

PoC
CVSS 3.1
8.8 high
EPSS
<1%p33
Published
()
Modified
Description

The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

Vendors
gsheetconnector
Products
woocommerce google sheet connector
Ecosystems
WordPress, E-commerce
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.