Unauthorized Data Modification Vulnerability in WPSyncSheets Lite for WPForms
CVE-2024-12164

4.3MEDIUM

Key Information:

Vendor
Creativewerkdesigns
Status
WPsyncsheets Lite For WPforms – WPforms Google Spreadsheet Addon
Vendor
CVE Published:
12 February 2025

Summary

The WPSyncSheets Lite for WPForms plugin, used for integrating Google Sheets, is susceptible to unauthorized changes due to a lack of capability checks in the wpsslwp_reset_settings() function. This vulnerability allows authenticated attackers with at least Subscriber-level access to reset crucial plugin settings, potentially leading to significant disruptions in data management. It affects all versions up to and including 1.6, making it essential for users to update to the latest version to safeguard against potential security breaches.

Affected Version(s)

WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon * <= 1.6

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kévin Mosbahi
.