What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in WPPOOL Sheets To WP Table Live Sync plugin <= 2.12.15 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in WPPOOL Sheets To WP Table Live Sync plugin <= 2.12.15 versions.
Explanation of Vulnerability in Simple Terms
Sheets To WP Table Live Sync versions up to 2.12.15 lack CSRF protection on key actions. An attacker can trick a logged-in site admin into visiting a malicious page that performs unwanted changes to the plugin's settings or data. The attack requires the admin to click a link or visit a page while authenticated.
What an attacker can do
Trick a logged-in admin into modifying plugin settings or data without their knowledge.
Potential impact on your site
Plugin settings or synced data could be altered by an attacker without your consent or awareness.
Conditions required to exploit
Admin must be logged in and visit an attacker-controlled page or click a malicious link.
Key dates
External resources
Related vulnerabilities