Medium severity6.1NVD Advisory· Published Jul 4, 2023· Updated Jun 17, 2026
CVE-2023-2320
CVE-2023-2320
Description
The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4<5.0.2+ 1 more
- (no CPE)range: <5.0.2
- (no CPE)
cpe:2.3:a:gsheetconnector:cf7_google_sheets_connector:*:*:*:*:pro:wordpress:*:*+ 1 more
- cpe:2.3:a:gsheetconnector:cf7_google_sheets_connector:*:*:*:*:pro:wordpress:*:*range: <=2.3.5
- cpe:2.3:a:gsheetconnector:cf7_google_sheets_connector:*:*:*:*:free:wordpress:*:*range: <5.0.2
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/f17ccbaa-2fcd-4f17-a4da-73f2bc8a4fe9nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.