CVE-2023-2329: WooCommerce Google Sheet Connector < 1.3.6 - Access Code Update via CSRF
The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Other sources
The WooCommerce Google Sheet Connector WordPress plugin through 1.3.4 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2329?
CVE-2023-2329 has a moderate severity level due to the potential for unauthorized access code changes through a CSRF attack.
How do I fix CVE-2023-2329?
To fix CVE-2023-2329, update the WooCommerce Google Sheet Connector plugin to version 1.3.6 or later.
Who is affected by CVE-2023-2329?
Users of the WooCommerce Google Sheet Connector WordPress plugin version 1.3.4 or earlier are affected by CVE-2023-2329.
What type of attack does CVE-2023-2329 involve?
CVE-2023-2329 involves a Cross-Site Request Forgery (CSRF) attack that can exploit the lack of CSRF checks.
What can attackers do with CVE-2023-2329?
With CVE-2023-2329, attackers can change the access code to an arbitrary one if they manage to execute a CSRF attack on a logged-in admin.