Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-2329

Description

The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack

POC

Reference

- https://wpscan.com/vulnerability/6e58f099-e8d6-49e4-9f02-d6a556c5b1d2

Github

- https://github.com/20142995/nuclei-templates