PT-2025-47833 · WordPress · Gsheetconnector For Ninja Forms

Hardik Patel

·

Published

2025-11-22

·

Updated

2025-11-22

·

CVE-2025-13136

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GSheetConnector For Ninja Forms plugin for WordPress versions up to and including 2.0.1
Description The GSheetConnector For Ninja Forms plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check on the 'njform-google-sheet-config' page. Authenticated attackers with Subscriber-level access or higher can retrieve system information.
Recommendations Update GSheetConnector For Ninja Forms plugin for WordPress to a version later than 2.0.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13136

Affected Products

Gsheetconnector For Ninja Forms