Description
The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is due to a missing capability check on the 'install_plugin' function. This makes it possible for authenticated attackers, with subscriber-level access and above to install plugins on the target site and potentially achieve arbitrary code execution on the server under certain conditions.
Problem types
Product status
*
Timeline
2025-07-25: | Discovered |
2025-08-21: | Vendor Notified |
2025-10-10: | Disclosed |
Credits
wesley
References
www.wordfence.com/...-2853-4c5d-9e36-8c5b7418b072?source=cve
plugins.trac.wordpress.org/...ass-gravityform-gs-service.php
plugins.trac.wordpress.org/...ty-forms&sfp_email=&sfph_mail=