8.8

CVE-2023-2329

Exploit

WooCommerce Google Sheet Connector < 1.3.6 - Access Code Update via CSRF

WooCommerce Google Sheet Connector < 1.3.6 - Cross-Site Request Forgery

The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Mögliche Gegenmaßnahme
GSheetConnector – WooCommerce Google Sheets Connector, Export Orders & Products to Google Sheets in Real-Time: Update to version 1.3.6, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gsheetconnector ≫ Woocommerce Google Sheet Connector SwPlatform wordpress Version <= 1.3.4
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt GSheetConnector – WooCommerce Google Sheets Connector, Export Orders & Products to Google Sheets in Real-Time
Version *-1.3.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.309
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/6e58f099-e8d6-49e4-9f02-d6a556c5b1d2
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/e30e64e7-5de9-4eb3-914f-457daa6f3fe5
Third Party Advisory