WPGSI: Spreadsheet Integration <= 3.8.3 - Missing Authorization to Unauthenticated Arbitrary Post Creation and Deletion via Forged Base64 Token
WPGSI: Spreadsheet Integration
Minimum safe version
3.8.4
Update to 3.8.4 or later to address 12 fixable vulnerabilities
WordPress Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Plugin <= 3.8.2 is vulnerable to Cross Site Request Forgery (CSRF)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-6590
Spreadsheet Integration < 3.6.0 - Reflected Cross-Site Scripting
Spreadsheet Integration < 3.6.0 - CSRF Bypass
WordPress Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Plugin <= 3.7.8 is vulnerable to Cross Site Scripting (XSS)
Spreadsheet Integration and Spreadsheet Integration Pro <= 3.5.0 - Cross-Site Request Forgery
Spreadsheet Integration and Spreadsheet Integration Pro <= 3.5.0 - Reflected Cross-Site Scripting
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins plugin <= 3.6.0 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
WordPress Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins plugin <= 3.6.0 - Sensitive Information Disclosure vulnerability