SQL Injection Vulnerability in CF7 Google Sheets Connector Plugin for WordPress
CVE-2026-16614
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-16614?
The CF7 Google Sheets Connector plugin for WordPress is prone to SQL Injection vulnerabilities due to inadequate escaping of user-supplied parameters in the 's' parameter. This affects all versions up to and including 5.2.1. Authenticated users with administrator-level access can exploit this weakness to inject malicious SQL queries that may leak sensitive database information. The plugin's reliance on wp_unslash() and sanitize_text_field() does not properly handle SQL metacharacters, leaving them intact and vulnerable to manipulation within SQL queries.
Affected Version(s)
GSheetConnector β CF7 Google Sheets Connector 0 <= 5.2.1