CVE-2024-1562
21.02.2024, 04:15
The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers to update plugin settings.Enginsight
Vendor | Product | Version |
---|---|---|
gsheetconnector | woocommerce_google_sheet_connector | 𝑥 ≤ 1.3.11 |
gsheetconnector | woocommerce_google_sheet_connector | 𝑥 < 1.3.12 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References