CVE-2023-2324: Elementor Forms Google Sheet Connector < 1.0.7 - Reflected XSS
The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-2324.
What is the affected software?
The affected software is the Elementor Forms Google Sheet Connector WordPress plugin before version 1.0.7 and the gsheetconnector-for-elementor-forms-pro WordPress plugin through version 1.0.7.
What is the severity of CVE-2023-2324?
The severity of CVE-2023-2324 is medium with a CVSS score of 6.1.
What is the CWE category for this vulnerability?
The CWE category for this vulnerability is CWE-79.
How can I fix CVE-2023-2324?
To fix CVE-2023-2324, you should update the Elementor Forms Google Sheet Connector WordPress plugin to version 1.0.7 or higher, or the gsheetconnector-for-elementor-forms-pro WordPress plugin to version 1.0.7 or higher.