CVE-2023-2333: Ninja Forms Google Sheet Connector < 1.2.7 - Reflected XSS
Published Jul 4, 2023
·Updated
The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
2 affected components
GSheetConnector Ninja Forms Google Sheet Connector WordPress<1.2.7
GSheetConnector Ninja Forms Google Sheet Connector WordPress<=1.2.7
Event History
Jul 4, 2023
CVE Published
via MITRE·07:23 AM
Data Sourced
via MITRE·07:23 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-2333?
The severity of CVE-2023-2333 is rated as medium with a CVSS score of 6.1.
2
How can I fix CVE-2023-2333 in Ninja Forms Google Sheet Connector plugin?
To fix CVE-2023-2333, update the Ninja Forms Google Sheet Connector plugin to version 1.2.7 or higher.