CVE Database /
CVE-2023-2320
CVE · Medium
CVE-2023-2320 — GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database [cf7-google-sheets-connector] < 5.0.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-2320
|
GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database [cf7-google-sheets-connector] < 5.0.2 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 5.0.2
|
5.0.2 |
2023-06-12 |
—
|
CVE-2023-2320
The CF7 Google Sheets Connector plugin versions before 5.0.2 contain a cross-site scripting vulnerability that could enable attackers to inject malicious scripts into a website, potentially executing redirects, advertisements, and arbitrary HTML when visitors access the site. This flaw was discovered by Erwan LR and has been patched in version 5.0.2 and later. Users should upgrade to at least version 5.0.2 to eliminate this risk.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings