First published: Tue Jul 04 2023(Updated: )
The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Contact Form 7 | <=2.3.5 | |
Contact Form 7 | <5.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2320 is classified as a high severity vulnerability due to its potential for Reflected Cross-Site Scripting attacks.
To fix CVE-2023-2320, update the CF7 Google Sheets Connector plugin to version 5.0.2 or later.
CVE-2023-2320 affects versions up to 5.0.2 of the CF7 Google Sheets Connector plugin for WordPress.
CVE-2023-2320 is a Reflected Cross-Site Scripting vulnerability.
CVE-2023-2320 could be exploited by any attacker with the ability to craft a malicious request targeting users of the vulnerable plugin.