VDB

CVE-2023-2334

CVE-2023-2334 PUBLISHED CVSS 6.800000190734863 MEDIUM

The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

EPSS 0.18% · 7.4th percentile

Risk Scores

CVSS 4.0
6.800000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.18%
7.4th percentile

Affected Products

VendorProductVersions
UnknownEasy Digital Downloads Google Sheet Connector0, 0
Unknownedd-google-sheet-connector-pro0, 0
gsheetconnectoredd_gsheetconnector0, 0
westerndealeasy_digital_downloads_google_sheet_connector0, 0

Timeline

  • May 15, 2025 CVE Published
  • May 16, 2025 EPSS Score
  • May 16, 2025 CVE Updated
  • May 28, 2025 EPSS Score
  • Jun 8, 2025 EPSS Score
  • Jun 20, 2025 EPSS Score
  • Jul 1, 2025 EPSS Score
  • Jul 13, 2025 EPSS Score
  • Jul 24, 2025 EPSS Score
  • Aug 5, 2025 EPSS Score
  • Aug 16, 2025 EPSS Score
  • Aug 28, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›