cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forgsheetconnector-ninja-forms gsheetconnector-ninja-forms

Direction: ascending
Jun 07, 2024

Ninja Forms Google Sheet Connector # 48c876c4c37ae47cdbba572acd132e945788cdbd

Date
Feb 28, 2022
Research Description
Ninja Forms Google Sheet Connector [gsheetconnector-ninja-forms] < 1.2.2 WordPress Ninja Forms Google Sheet Connector plugin < 1.2.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Ninja Forms Google Sheet Connector plugin (versions < 1.2.2).
Affected versions
max 1.2.2.
Status
vulnerable

Ninja Forms Google Sheet Connector # CVE-2023-2333

CVE, Research URL

CVE-2023-2333

Date
Jul 04, 2023
Research Description
The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected versions
max 1.2.7.
Status
vulnerable
Dec 10, 2025

Ninja Forms Google Sheet Connector # CVE-2025-13136

CVE, Research URL

CVE-2025-13136

Date
Nov 22, 2025
Research Description
The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'njform-google-sheet-config ' page in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve information about the system.
Affected versions
max 2.0.2.
Status
vulnerable