VDB
CVE-2023-2324
CVE-2023-2324
PUBLISHED
CVSS 6.099999904632568 MEDIUM
The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
EPSS 0.46% · 39.0th percentile
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.46%
39.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unknown | gsheetconnector-for-elementor-forms-pro | 0, 0 |
| Unknown | Elementor Forms Google Sheet Connector | 0, 0 |
| gsheetconnector | elementor_forms_google_sheet_connector | 0, 0, 0 |
Timeline
- Jul 4, 2023 EPSS Score
- Jul 4, 2023 CVE Published
- Aug 8, 2023 EPSS Score
- Sep 12, 2023 EPSS Score
- Oct 18, 2023 EPSS Score
- Nov 22, 2023 EPSS Score
- Jan 31, 2024 EPSS Score
- Mar 6, 2024 EPSS Score
- Apr 11, 2024 EPSS Score
- May 16, 2024 EPSS Score
- Jun 20, 2024 EPSS Score
- Jul 25, 2024 EPSS Score