Spreadsheet Integration and Spreadsheet Integration Pro <= 3.5.0 - Cross-Site Request Forgery
high
The Spreadsheet Integration and Spreadsheet Integration Professional plugins for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.0. This is due to missing or incorrect nonce validation on the 'wpgsi_WorksheetColumnsTitle' function. This makes it possible for unauthenticated a...
- CVSS:
- 8.8
- Affected:
- up to 3.5.0
- Fixed in:
- 3.6.0
- Disclosed:
- Dec 24, 2021
Spreadsheet Integration and Spreadsheet Integration Pro <= 3.5.0 - Reflected Cross-Site Scripting
medium
The Spreadsheet Integration and Spreadsheet Integration Professional plugins for WordPress are vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...
- CVSS:
- 6.1
- Affected:
- up to 3.5.0
- Fixed in:
- 3.6.0
- Disclosed:
- Dec 24, 2021
Spreadsheet Integration Professional [wpgsi-professional] < 3.6.0
unknown
The plugin does not properly check for CSRF in its wpgsi_WorksheetColumnsTitle function, by making a request without the nonce parameter. This could allow attacker to make logged in admins call it
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
Spreadsheet Integration Professional [wpgsi-professional] < 3.6.0
unknown
The plugin does not sanitise or escape some parameters before outputting them back in the admin dashboard, leading to reflected Cross-Site Scripting issues
- Affected:
- up to 3.6.0
- Fixed in:
- 3.6.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database