VDB
CVE-2024-1562
CVE-2024-1562
PUBLISHED
CVSS 5.300000190734863 MEDIUM
The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers to update plugin settings.
EPSS 0.43% · 36.6th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.43%
36.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| gsheetconnector | woocommerce_google_sheet_connector | 0, 0 |
| westerndeal | GSheetConnector for WooCommerce – Send your Orders and Products to Google Sheet in Real-Time | 0 |
| westerndeal | WooCommerce Google Sheet Connector | * |
| gsheetconnector | woocommerce_google_sheet_connector | 0, 0 |
Timeline
- Feb 21, 2024 EPSS Score
- Feb 21, 2024 CVE Published
- Feb 21, 2024 PoC Published
- Feb 21, 2024 PoC Published
- Feb 22, 2024 PoC Published
- Mar 8, 2024 PoC Published
- Mar 19, 2024 EPSS Score
- Apr 15, 2024 EPSS Score
- May 12, 2024 EPSS Score
- Jul 5, 2024 EPSS Score
- Aug 1, 2024 EPSS Score
- Sep 1, 2024 EPSS Score
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/e36df7b7-fcbc-4e5d-812c-861bfe8abb55?source=cve url
- https://nvd.nist.gov/vuln/detail/CVE-2024-1562 advisory
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3038517%40wc-gsheetconnector&new=3038517%40wc-gsheetconnector&sfp_email=&sfph_mail= url