VDB

CVE-2023-2326

CVE-2023-2326 PUBLISHED CVSS 6.5 MEDIUM

The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

EPSS 0.31% · 23.7th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
0.31%
23.7th percentile

Affected Products

VendorProductVersions
Unknowngsheetconnector-gravityforms-pro0, 0
UnknownGravity Forms Google Sheet Connector0, 0
gsheetconnectorgravity_forms_google_sheets_connector0, 0

Timeline

  • Jun 27, 2023 CVE Published
  • Jun 28, 2023 EPSS Score
  • Aug 2, 2023 EPSS Score
  • Sep 7, 2023 EPSS Score
  • Oct 12, 2023 EPSS Score
  • Dec 22, 2023 EPSS Score
  • Jan 26, 2024 EPSS Score
  • Mar 1, 2024 EPSS Score
  • Apr 6, 2024 EPSS Score
  • May 11, 2024 EPSS Score
  • Jun 15, 2024 EPSS Score
  • Jul 21, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›