CVE-2023-2330: Caldera Forms Google Sheets Connector < 1.3 - Access Code Update via CSRF
The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Other sources
The Caldera Forms Google Sheets Connector WordPress plugin through 1.2 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2330?
CVE-2023-2330 is classified as a high-severity vulnerability due to the potential for unauthorized access code changes.
How do I fix CVE-2023-2330?
To fix CVE-2023-2330, update the Caldera Forms Google Sheets Connector plugin to version 1.3 or later.
What does CVE-2023-2330 affect?
CVE-2023-2330 affects the Caldera Forms Google Sheets Connector WordPress plugin versions prior to 1.3.
What type of attack is associated with CVE-2023-2330?
CVE-2023-2330 is related to a Cross-Site Request Forgery (CSRF) attack that can change the access code.
Who is impacted by CVE-2023-2330?
Logged-in administrators of WordPress sites using the affected version of the Caldera Forms Google Sheets Connector are at risk due to CVE-2023-2330.