CVE · Medium

CVE-2023-2320 — GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database [cf7-google-sheets-connector] < 5.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-2320 GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database [cf7-google-sheets-connector] < 5.0.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 5.0.2 5.0.2 2023-06-12

CVE-2023-2320

The CF7 Google Sheets Connector plugin versions before 5.0.2 contain a cross-site scripting vulnerability that could enable attackers to inject malicious scripts into a website, potentially executing redirects, advertisements, and arbitrary HTML when visitors access the site. This flaw was discovered by Erwan LR and has been patched in version 5.0.2 and later. Users should upgrade to at least version 5.0.2 to eliminate this risk.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.