Authorization Bypass in GSheetConnector for Gravity Forms Plugin by WordPress
CVE-2025-8593
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 11 October 2025
What is CVE-2025-8593?
The GSheetConnector for Gravity Forms plugin is vulnerable due to a missing capability check in the 'install_plugin' function, affecting all versions up to 1.3.27. This vulnerability allows authenticated users with subscriber-level access and higher to bypass the expected authorization, enabling them to install plugins on the target site. This action could lead to potential arbitrary code execution on the server, particularly under specific circumstances. It highlights the need for strict access controls to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GSheetConnector For Gravity Forms * <= 1.3.27
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved