Cross-Site Request Forgery in PluginsCafe Address Autocomplete for Gravity Forms
CVE-2025-53263

5.4MEDIUM

What is CVE-2025-53263?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the PluginsCafe Address Autocomplete via Google for Gravity Forms plugin, impacting versions up to 1.3.4. This security flaw allows attackers to perform unauthorized actions on behalf of authenticated users, potentially compromising the integrity of user data and the site's functionality.

Affected Version(s)

Address Autocomplete via Google for Gravity Forms <= 1.3.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.