CVE-2023-2334: Easy Digital Downloads Google Sheet Connector < 1.6.6 - Access Code Update via CSRF
The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2334?
CVE-2023-2334 is classified as a medium severity vulnerability due to the lack of CSRF protection in the affected plugins.
How do I fix CVE-2023-2334?
To fix CVE-2023-2334, update the Easy Digital Downloads Google Sheet Connector to version 1.6.6 or higher and the Pro version to 1.4 or higher.
What are the risks associated with CVE-2023-2334?
The risks associated with CVE-2023-2334 include unauthorized access and modification of the access code by attackers exploiting the CSRF vulnerability.
Which versions are affected by CVE-2023-2334?
CVE-2023-2334 affects Easy Digital Downloads Google Sheet Connector versions before 1.6.6 and Easy Digital Downloads Google Sheet Connector Pro versions before 1.4.
Who is impacted by CVE-2023-2334?
Users of the affected versions of the Easy Digital Downloads Google Sheet Connector plugins on their WordPress sites are impacted by CVE-2023-2334.