CVE-2023-2320: CF7 Google Sheets Connector < 5.0.2 - Reflected XSS
The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2320?
CVE-2023-2320 is classified as a high severity vulnerability due to its potential for Reflected Cross-Site Scripting attacks.
How do I fix CVE-2023-2320?
To fix CVE-2023-2320, update the CF7 Google Sheets Connector plugin to version 5.0.2 or later.
What systems are affected by CVE-2023-2320?
CVE-2023-2320 affects versions up to 5.0.2 of the CF7 Google Sheets Connector plugin for WordPress.
What type of vulnerability is CVE-2023-2320?
CVE-2023-2320 is a Reflected Cross-Site Scripting vulnerability.
Who could exploit CVE-2023-2320?
CVE-2023-2320 could be exploited by any attacker with the ability to craft a malicious request targeting users of the vulnerable plugin.