Lucene search

K
wpexploitWpvulndbWPEX-ID:6E58F099-E8D6-49E4-9F02-D6A556C5B1D2
HistoryJun 26, 2023 - 12:00 a.m.

WooCommerce Google Sheet Connector <= 1.3.5 - Access Code Update via CSRF

2023-06-2600:00:00
wpvulndb
80
woocommerce
google sheet
connector
csrf
vulnerability
admin
exploit
update

EPSS

0.002

Percentile

57.0%

The plugin does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

Make a logged in admin open https://example.com/wp-admin/admin.php?page=wc-gsheetconnector-config&code=attacker-code

EPSS

0.002

Percentile

57.0%

Related for WPEX-ID:6E58F099-E8D6-49E4-9F02-D6A556C5B1D2