VYPR
Unrated severityNVD Advisory· Published Jun 27, 2023· Updated Nov 27, 2024

Gravity Forms Google Sheet Connector < 1.3.5 - Access Code Update via CSRF

CVE-2023-2326

Description

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.