First published: Tue Jul 04 2023(Updated: )
The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gsheetconnector for Forminator Forms WordPress | <1.0.7 | |
Gsheetconnector for Forminator Forms WordPress | <=1.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-2324.
The affected software is the Elementor Forms Google Sheet Connector WordPress plugin before version 1.0.7 and the gsheetconnector-for-elementor-forms-pro WordPress plugin through version 1.0.7.
The severity of CVE-2023-2324 is medium with a CVSS score of 6.1.
The CWE category for this vulnerability is CWE-79.
To fix CVE-2023-2324, you should update the Elementor Forms Google Sheet Connector WordPress plugin to version 1.0.7 or higher, or the gsheetconnector-for-elementor-forms-pro WordPress plugin to version 1.0.7 or higher.