VDB
CVE-2023-2334
CVE-2023-2334
PUBLISHED
CVSS 6.800000190734863 MEDIUM
The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
EPSS 0.18% · 7.4th percentile
Risk Scores
CVSS 4.0
6.800000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.18%
7.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Easy Digital Downloads Google Sheet Connector | 0, 0 |
| Unknown | edd-google-sheet-connector-pro | 0, 0 |
| gsheetconnector | edd_gsheetconnector | 0, 0 |
| westerndeal | easy_digital_downloads_google_sheet_connector | 0, 0 |
Timeline
- May 15, 2025 CVE Published
- May 16, 2025 EPSS Score
- May 16, 2025 CVE Updated
- May 28, 2025 EPSS Score
- Jun 8, 2025 EPSS Score
- Jun 20, 2025 EPSS Score
- Jul 1, 2025 EPSS Score
- Jul 13, 2025 EPSS Score
- Jul 24, 2025 EPSS Score
- Aug 5, 2025 EPSS Score
- Aug 16, 2025 EPSS Score
- Aug 28, 2025 EPSS Score