Authorization Bypass in GSheetConnector for Gravity Forms Plugin by WordPress
CVE-2025-8593
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 October 2025
What is CVE-2025-8593?
The GSheetConnector for Gravity Forms plugin is vulnerable due to a missing capability check in the 'install_plugin' function, affecting all versions up to 1.3.27. This vulnerability allows authenticated users with subscriber-level access and higher to bypass the expected authorization, enabling them to install plugins on the target site. This action could lead to potential arbitrary code execution on the server, particularly under specific circumstances. It highlights the need for strict access controls to prevent exploitation.
Affected Version(s)
GSheetConnector For Gravity Forms * <= 1.3.27