CVE-2023-32117: WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability

9.8 CVSS

Description

Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

Classification

CVE ID: CVE-2023-32117

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.8

Affected Products

Vendor: SoftLab

Product: Integrate Google Drive

Nuclei Template

http/cves/2023/CVE-2023-32117.yaml

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.25% (probability of being exploited)

EPSS Percentile: 64.31% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://patchstack.com/database/wordpress/plugin/integrate-google-drive/vulnerability/wordpress-integrate-google-drive-plugin-1-1-99-unauthenticated-broken-access-control-vulnerability?_s_id=cve

Timeline