CVE-2023-32117
📛 CVE Title
WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability
Description
Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Patchstack
- CVSS severity
- CRITICAL
- CVSS score
- 9.8 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Effective score
- 9.8 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-862 - Reserved
- 2023-05-03
- Published
- 2024-12-09 12:30 UTC
- Last updated
- 2026-04-28 18:08 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/32xxx/CVE-2023-32117.json
- Linked Threat
- CVE-2023-32117 — Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-36385 - Assigner
- Patchstack
- Published
- Dec 9, 2024, 11:30:57 AM
- Updated
- Apr 28, 2026, 4:08:21 PM
- EUVD base score (CVSS 3.1)
-
9.8 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 89.3800
- Vendors
- princeahmed, SoftLab
- Products
-
Integrate Google Drive (0 ≤1.1.99)Integrate Google Drive (n/a ≤1.1.99)
- Aliases
-
GHSA-fc7x-ffxp-c9q2
ENISA description: Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| SoftLab | Integrate Google Drive |
n/a (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- http://cwe.mitre.org/data/definitions/862.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2023-32117 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-36385 rapid7:euvd.enisa.europa.eu
- https://www.cve.org/CVERecord?id=CVE-2023-32117 rapid7:www.cve.org
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6fe8b2c8-3bb1-463a-a64c-15d7bcc29985?source=api-prod rapid7:www.wordfence.com
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| domain |
levels.this
|
no local data | 2026-05-18 21:19 UTC |
| cve |
CVE-2023-32117
|
no local data | 2026-06-06 15:01 UTC |
Remediations (23)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:portal.msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-06-13 19:35 UTC -
web:www.oracle.com
Oracle Critical Patch Update Advisory - July 2025 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...
2026-06-13 19:35 UTC -
web:www.hipaajournal.com
CISA's solution is to patch smarter, not harder. CISA has released a new risk-based vulnerability remediation framework to help vendors assess vulnerabilities and prioritize patching effectively, concentrating their efforts on mitigating vulnerabilities in the most at-risk assets and addressing vulnerabilities that carry the greatest risk of ...
2026-06-13 19:35 UTC -
web:www.cisa.gov
The median time for full resolution rose to 43 days. Defenders need greater clarity and speed to patch systems in today's threat landscape. We must flip the script on patching prioritization: patch smarter, not harder.
2026-06-13 19:35 UTC -
web:github.com
CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software - secureIT-project/CVEfixes
2026-06-13 19:35 UTC -
Wordfence remediation: File Manager for Google Drive – Integrate Google DriveWordfence
Update to version 1.2.0, or a newer patched version
2026-06-06 15:01 UTC -
web:www.ninjaone.com
The update is delivered through standard Windows Update channels and is recommended as part of regular maintenance routines. The patch resolves six distinct security vulnerabilities ranging from remote code execution to information disclosure issues, alongside reliability enhancements for Windows Communication Foundation (WCF) services.
2026-05-22 06:30 UTC -
web:github.com
A new and improved community patch for BO3. . Contribute to shiversoftdev/t7patch development by creating an account on GitHub.
2026-05-22 06:30 UTC -
web:cyberpress.org
A newly published proof-of-concept tool called BitUnlocker exposes a dangerous downgrade attack that can bypass Microsoft's BitLocker full-disk encryption on fully patched Windows 11 machines, granting complete access to encrypted drives in under five minutes. The attack exploits CVE -2025-48804, a vulnerability in Windows BitLocker that allows an attacker to mix untrusted data with trusted ...
2026-05-22 06:30 UTC -
web:www.pcworld.com
Windows 11's Secure Boot fix update finally rolls out to more PCs Important security certificates for Windows 11 will soon expire for many users.
2026-05-22 06:30 UTC -
web:www.rapid7.com
Microsoft is publishing 66 new vulnerabilities today, which is far fewer than we've come to expect in recent months. However, the lone zero-day vulnerability this month demands attention.
2026-05-22 06:30 UTC -
web:www.forbes.com
Microsoft starts expiring critical Secure Boot certificates in just 2 weeks.
2026-05-22 06:30 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-22 06:30 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-05-22 04:19 UTC -
web:www.techrepublic.com
Microsoft's April 2026 Patch Tuesday fixes 165 vulnerabilities, including two zero-days, in one of the company's largest monthly security updates.
2026-05-22 04:19 UTC -
web:heimdalsecurity.com
Explore six essential patch management best practices for 2026 to keep your systems secure, up to date, and protected from vulnerabilities.
2026-05-22 04:19 UTC -
web:adaptiva.com
Identify threats with CrowdStrike Exposure Management and fix vulnerabilities quickly with OneSite Patch . Prioritize deployments based on CrowdStrike's ExPRT.ai to ensure rapid remediation as soon as a patch is available.
2026-05-22 04:19 UTC -
web:help.eset.com
Patch management helps ensure that systems and applications are secure against known vulnerabilities and exploits. The Patch management section lists all available patches remedying the detected vulnerabilities and makes the remediation process easier through automated software updates.
2026-05-22 04:19 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 04:19 UTC -
web:source.android.com
This Section contains the available Android Security Bulletins, which provide fixes for possible issues affecting Android devices.
2026-05-22 04:19 UTC -
web:github.com
Patch termsrv.dll so that multiple remote users can open an RDP session on a non-Windows Server computer - fabianosrc/TermsrvPatcher
2026-05-22 04:19 UTC -
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
2026-05-22 04:19 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-05-22 04:19 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-32117.json.
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:softlab:integrate_google_drive:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "integrate_google_drive",
"vendor": "softlab",
"versions": [
{
"lessThanOrEqual": "1.1.99",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-32117",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-12-09T16:46:27.207793Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-12-09T16:47:52.815Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "integrate-google-drive",
"product": "Integrate Google Drive",
"vendor": "SoftLab",
"versions": [
{
"changes": [
{
"at": "1.2.0",
"status": "unaffected"
}
],
"lessThanOrEqual": "1.1.99",
"status": "affected",
"version": "n/a",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Abdi Pranata (Patchstack Alliance)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.</p><p>This issue affects Integrate Google Drive: from n/a through 1.1.99.</p>"
}
],
"value": "Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99."
}
],
"impacts": [
{
"capecId": "CAPEC-180",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-180 Exploiting Incorrectly Configured Access Control Security Levels"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862 Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-28T16:08:21.890Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/wordpress/plugin/integrate-google-drive/vulnerability/wordpress-integrate-google-drive-plugin-1-1-99-unauthenticated-broken-access-control-vulnerability?_s_id=cve"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Update the WordPress Integrate Google Drive plugin to the latest available version (at least 1.2.0)."
}
],
"value": "Update the WordPress Integrate Google Drive plugin to the latest available version (at least 1.2.0)."
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "WordPress Integrate Google Drive plugin <= 1.1.99 - Unauthenticated Broken Access Control vulnerability",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2023-32117",
"datePublished": "2024-12-09T11:30:57.774Z",
"dateReserved": "2023-05-03T15:31:08.029Z",
"dateUpdated": "2026-04-28T16:08:21.890Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}