CVE-2023-2326: Gravity Forms Google Sheet Connector < 1.3.5 - Access Code Update via CSRF
The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2326?
CVE-2023-2326 has a high severity rating due to the potential for unauthorized access code changes.
How do I fix CVE-2023-2326?
To fix CVE-2023-2326, update the Gravity Forms Google Sheets Connector plugin to version 1.3.5 or later.
What are the consequences of CVE-2023-2326?
The consequences of CVE-2023-2326 include possible unauthorized modifications to access codes, which could compromise data security.
Who is affected by CVE-2023-2326?
CVE-2023-2326 affects users of the Gravity Forms Google Sheets Connector plugin versions prior to 1.3.5.
What type of vulnerability is CVE-2023-2326?
CVE-2023-2326 is a Cross-Site Request Forgery (CSRF) vulnerability that allows unauthorized access code changes.