PT-2025-41677 · WordPress+1 · Gsheetconnector For Gravity Forms+1

Wesley

·

Published

2025-10-11

·

Updated

2025-10-16

·

CVE-2025-8593

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GSheetConnector For Gravity Forms plugin for WordPress versions prior to 1.3.28
Description The GSheetConnector For Gravity Forms plugin for WordPress is susceptible to an authorization bypass. This occurs because of a missing capability check on the install plugin function. Attackers with subscriber-level access or higher can install plugins on the target site, potentially leading to arbitrary code execution on the server.
Recommendations Update the GSheetConnector For Gravity Forms plugin to version 1.3.28 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-8593

Affected Products

Gsheetconnector For Gravity Forms
Gravity Forms