CVE Published: 04/07/2023 |
CVE Updated: 21/11/2024 |
CVE Year: 2023 Source: WPScan |
Vendor: Unknown |
Product: Elementor Forms Google Sheet Connector Status : PUBLISHED
CVE-2023-2324 Description
The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin