CVE Database /
CVE-2024-5654
CVE · Medium
CVE-2024-5654 — GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database [cf7-google-sheets-connector] < 5.0.10
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-5654
|
GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database [cf7-google-sheets-connector] < 5.0.10 |
Missing Authorization |
Medium
6.5
|
< 5.0.10
|
5.0.10 |
2024-06-07 |
—
|
CVE-2024-5654
The CF7 Google Sheets Connector plugin contains a vulnerability in versions up to 5.0.9 where the execute_post_data_cg7_free function lacks proper permission validation, allowing unauthenticated users to modify site configuration. Attackers can exploit this flaw to toggle critical WordPress settings such as WP_DEBUG, WP_DEBUG_LOG, SCRIPT_DEBUG, and SAVEQUERIES without authorization. The vulnerability was fixed in version 5.0.10.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings