The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/f922695a-b803-4edf-aadc-80c79d99bebb | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/f922695a-b803-4edf-aadc-80c79d99bebb | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2023-06-27 14:15
Updated : 2024-11-21 07:58
NVD link : CVE-2023-2326
Mitre link : CVE-2023-2326
CVE.ORG link : CVE-2023-2326
JSON object : View
Products Affected
                gsheetconnector
- gravity_forms_google_sheets_connector
CWE
                No CWE.
