cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwc-gsheetconnector wc-gsheetconnector

Direction: ascending
Jun 07, 2024

WooCommerce Google Sheet Connector # CVE-2023-2329

CVE, Research URL

CVE-2023-2329

Date
Jul 17, 2023
Research Description
The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Affected versions
Min -, max -.
Status
vulnerable

WooCommerce Google Sheet Connector # 3e863c052e052b56e939369330fb66f458278d6f

Date
Feb 28, 2022
Research Description
WooCommerce Google Sheet Connector [wc-gsheetconnector] < 1.2.3 WordPress WooCommerce Google Sheet Connector plugin <= 1.2.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress WooCommerce Google Sheet Connector plugin (versions <= 1.2.2).
Affected versions
Min -, max -.
Status
vulnerable

WooCommerce Google Sheet Connector # CVE-2024-1562

CVE, Research URL

CVE-2024-1562

Date
Feb 21, 2024
Research Description
The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function in all versions up to, and including, 1.3.11. This makes it possible for unauthenticated attackers to update plugin settings.
Affected versions
Min -, max -.
Status
vulnerable
Jul 18, 2025

WooCommerce Google Sheet Connector # CVE-2025-54030

CVE, Research URL

CVE-2025-54030

Date
Jul 16, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in GSheetConnector by WesternDeal WooCommerce Google Sheet Connector allows Cross Site Request Forgery. This issue affects WooCommerce Google Sheet Connector: from n/a through 1.3.20.
Affected versions
Min -, max -.
Status
vulnerable