Gsheetconnector provides a family of WordPress form and e-commerce connectors that integrate with Google Sheets, with plugins spanning Contact Form 7, WooCommerce, Caldera Forms, Easy Digital Downloads, and Elementor. The recurring vulnerability pattern centers on web-application security issues—missing authorization controls, cross-site request forgery, and cross-site scripting—reflecting the authentication and input-handling demands of form processors that bridge third-party services. Current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gsheetconnector over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2329HIGH The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin cha | Jul 17, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-2330HIGH The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin ch | Jul 17, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-5654MEDIUM The CF7 Google Sheets Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'execute_post_data_cg7_free' functi | Jun 8, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-44989HIGH Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue affects CF7 Google Sheets Connector: from n/a through 5.0.5 | Mar 26, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-2320MEDIUM The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back | Jul 4, 2023 | 6.1 | 20 | NO | NO |
CVE-2025-22752MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WesternDeal GSheetConnector for Forminator Forms gsheetconnector-forminator al | Jan 15, 2025 | 6.1 | 18 | NO | NO |
CVE-2023-2333MEDIUM The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting i | Jul 4, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-2324MEDIUM The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters bef | Jul 4, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-2321MEDIUM The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back i | Jul 4, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-1562MEDIUM The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function i | Feb 21, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gsheetconnector.
Media articles that mention a CVE ID that affects a product developed by Gsheetconnector — matched by CVE ID, not by vendor name.