The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
2023-07-04T08:15:10.240
2024-11-21T07:58:22.920
Modified
CVSSv3.1: 6.1 (MEDIUM)
-
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gsheetconnector | cf7_google_sheets_connector | ≤ 2.3.5 | Yes |
Application | gsheetconnector | cf7_google_sheets_connector | < 5.0.2 | Yes |