Executive brief
The Integrate Google Drive plugin for WordPress, which allows users to manage and display Google Drive files on their websites, contains a security flaw in its access control system. This vulnerability allows unauthorized individuals to bypass security settings and perform actions they should not be allowed to, potentially leading to unauthorized file access or modification. This could result in the exposure of sensitive documents or disruption of website functionality.
Technical details
A Broken Access Control vulnerability (CWE-862: Missing Authorization) exists in the Prince Integrate Google Drive plugin for WordPress in versions up to and including 1.3.8. The flaw stems from a lack of proper authorization checks, authentication, or nonce tokens in certain functions. An unauthenticated remote attacker can exploit this to execute actions that should be restricted to higher-privileged users, potentially compromising the integrity and confidentiality of the Google Drive integration. The issue is resolved in version 1.3.91.
Affected products
- Prince Integrate Google Drive up to 1.3.8
Timeline
- 2024-03-05: other: Vulnerability reported by researcher
- 2024-04-22: advisory: Patchstack published advisory
- 2026-06-17: disclosed: CVE published to NVD