Cross-Site Request Forgery in EDD Google Sheet Connector and EDD Google Sheet Connector Pro Plugins
CVE-2023-2334
What is CVE-2023-2334?
The EDD Google Sheet Connector Pro plugin and its counterpart, the EDD Google Sheet Connector, are susceptible to Cross-Site Request Forgery (CSRF) vulnerabilities. By exploiting these vulnerabilities, an attacker could manipulate a logged-in admin to unknowingly change the access code to an arbitrary value. This type of attack can compromise the security of the application by allowing unauthorized access to sensitive functionalities.
Affected Version(s)
Easy Digital Downloads Google Sheet Connector 0 < 1.6.6
edd-google-sheet-connector-pro 0 < 1.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved