First published: Wed Feb 21 2024(Updated: )
The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers to update plugin settings.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gsheetconnector WooCommerce Google Sheet Connector | <=1.3.11 | |
<1.3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1562 has a medium severity rating, indicating that it can lead to unauthorized data modification.
To fix CVE-2024-1562, update the WooCommerce Google Sheet Connector plugin to version 1.3.12 or later.
All users of the WooCommerce Google Sheet Connector plugin on versions up to and including 1.3.11 are affected by CVE-2024-1562.
CVE-2024-1562 is a data modification vulnerability due to missing capability checks in the plugin.
Yes, CVE-2024-1562 can be exploited by unauthenticated attackers to modify plugin settings.