CVE · Medium

CVE-2024-5654 — GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database [cf7-google-sheets-connector] < 5.0.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5654 GSheetConnector – CF7 Google Sheets Connector & Save CF7 Entries to Database [cf7-google-sheets-connector] < 5.0.10 Missing Authorization Medium 6.5 < 5.0.10 5.0.10 2024-06-07

CVE-2024-5654

The CF7 Google Sheets Connector plugin contains a vulnerability in versions up to 5.0.9 where the execute_post_data_cg7_free function lacks proper permission validation, allowing unauthenticated users to modify site configuration. Attackers can exploit this flaw to toggle critical WordPress settings such as WP_DEBUG, WP_DEBUG_LOG, SCRIPT_DEBUG, and SAVEQUERIES without authorization. The vulnerability was fixed in version 5.0.10.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.