Vulnerabilities and security researches forgsheetconnector-ninja-forms gsheetconnector-ninja-forms
Direction: descendingJun 16, 2026
Ninja Forms Google Sheet Connector # f62006fa2935f40d13e2fe6b26a28ab5e43cf103
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 28, 2022
- Research Description
- GSheetConnector For Ninja Forms [gsheetconnector-ninja-forms] < 1.2.2 WordPress Ninja Forms Google Sheet Connector plugin < 1.2.2 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress Ninja Forms Google Sheet Connector plugin (versions < 1.2.2).
- Affected versions
-
max 1.2.2.
- Status
-
vulnerable
Ninja Forms Google Sheet Connector # b7d9c54a-9a9a-48ad-bb78-e30340963236
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- GSheetConnector For Ninja Forms [gsheetconnector-ninja-forms] < 1.2.2 Unauthorised AJAX Calls via Freemius The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a CSRF attack.
- Affected versions
-
max 1.2.2.
- Status
-
vulnerable
Jun 13, 2026
Ninja Forms Google Sheet Connector # CVE-2023-33999
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 11, 2026
- Research Description
- Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.
- Affected versions
-
max 1.2.8.
- Status
-
vulnerable
Dec 10, 2025
Ninja Forms Google Sheet Connector # CVE-2025-13136
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 22, 2025
- Research Description
- The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'njform-google-sheet-config ' page in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve information about the system.
- Affected versions
-
max 2.0.2.
- Status
-
vulnerable
Jun 07, 2024
Ninja Forms Google Sheet Connector # 48c876c4c37ae47cdbba572acd132e945788cdbd
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 28, 2022
- Research Description
- GSheetConnector For Ninja Forms [gsheetconnector-ninja-forms] < 1.2.2 WordPress Ninja Forms Google Sheet Connector plugin < 1.2.2 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Ninja Forms Google Sheet Connector plugin (versions < 1.2.2).
- Affected versions
-
max 1.2.2.
- Status
-
vulnerable
Ninja Forms Google Sheet Connector # CVE-2023-2333
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 04, 2023
- Research Description
- The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
- Affected versions
-
max 1.2.7.
- Status
-
vulnerable