Unauthorized Data Modification Vulnerability in WPSyncSheets Lite for WPForms
CVE-2024-12164
4.3MEDIUM
Key Information:
- Vendor
- Creativewerkdesigns
- Status
- WPsyncsheets Lite For WPforms – WPforms Google Spreadsheet Addon
- Vendor
- CVE Published:
- 12 February 2025
Summary
The WPSyncSheets Lite for WPForms plugin, used for integrating Google Sheets, is susceptible to unauthorized changes due to a lack of capability checks in the wpsslwp_reset_settings() function. This vulnerability allows authenticated attackers with at least Subscriber-level access to reset crucial plugin settings, potentially leading to significant disruptions in data management. It affects all versions up to and including 1.6, making it essential for users to update to the latest version to safeguard against potential security breaches.
Affected Version(s)
WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon * <= 1.6
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kévin Mosbahi