CVE-2023-2329

CVE-2023-2329: WooCommerce Google Sheet Connector < 1.3.6 - Access Code Update via CSRF

Vendor Unknown
Product WooCommerce Google Sheet Connector
Published July 17, 2023
Last update November 5, 2024

CVSS base score

What the vulnerability does

01Description

The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

Key dates

02Disclosure timeline

July 17, 2023 CVE published
November 5, 2024 Record updated