Medium severity6.1NVD Advisory· Published Jul 4, 2023· Updated Jun 17, 2026
CVE-2023-2324
CVE-2023-2324
Description
The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: <1.0.7
- Range: <=1.0.7
- WordPress/Elementor Forms Google Sheet Connectordescription
cpe:2.3:a:gsheetconnector:elementor_forms_google_sheet_connector:*:*:*:*:free:wordpress:*:*+ 1 more
- cpe:2.3:a:gsheetconnector:elementor_forms_google_sheet_connector:*:*:*:*:free:wordpress:*:*range: <1.0.7
- cpe:2.3:a:gsheetconnector:elementor_forms_google_sheet_connector:*:*:*:*:pro:wordpress:*:*range: <=1.0.7
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/50d81eec-f324-4445-b10f-96e94153917envdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.