Unauthorized Data Modification Vulnerability in WPSyncSheets Lite for WPForms
CVE-2024-12164
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 February 2025
What is CVE-2024-12164?
The WPSyncSheets Lite for WPForms plugin, used for integrating Google Sheets, is susceptible to unauthorized changes due to a lack of capability checks in the wpsslwp_reset_settings() function. This vulnerability allows authenticated attackers with at least Subscriber-level access to reset crucial plugin settings, potentially leading to significant disruptions in data management. It affects all versions up to and including 1.6, making it essential for users to update to the latest version to safeguard against potential security breaches.
Affected Version(s)
WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon * <= 1.6