Aller au contenu

Fiche vulnérabilité

CVE-2023-2334 : faille moyenne westerndeal easy digital downloads… (CVSS 5.4)

Description

The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
15 mai 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • westerndeal easy digital downloads google sheet connector
  • gsheetconnector edd gsheetconnector

Références

Rechercher une autre vulnérabilité dans la base CVE