WPForms Google Sheet Connector < 3.4.6 - Reflected XSS
CVE-2023-2321
6.1MEDIUM
What is CVE-2023-2321?
The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Version(s)
gsheetconnector-wpforms-pro 0 <= 3.4.6
WPForms Google Sheet Connector 0 < 3.4.6