Description
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms integration-for-contact-form-7-and-google-sheets allows Cross Site Request Forgery.This issue affects Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through <= 1.0.9.
Published: 2025-03-27
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Cross‑Site Request Forgery (CSRF) exists in the CRM Perks Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin. An attacker can craft a request that a logged‑in WordPress user unknowingly submits, causing the plugin to perform actions such as adding or modifying data without the user's consent. The flaw is a classic CSRF vulnerability (CWE‑352) that jeopardizes the integrity and authenticity of the user's data within the plugin, although it does not directly expose privileged system resources.

Affected Systems

The vulnerability affects the CRM Perks Integration for Google Sheets and Contact Form 7 plugin and its bundled integrations for Contact Form 7, WPForms, Elementor, and Ninja Forms. All released versions up to and including 1.0.9 are vulnerable, as the plug‑in’s CSRF checks are missing until a patch beyond 1.0.9 is released. The affected product is a WordPress plugin that connects form submissions to Google Sheets.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact, but the EPSS score of less than 1 % shows that this flaw is unlikely to be actively exploited. It is not listed in the CISA KEV catalog. Exploitation requires a legitimate user account with sufficient privileges and a crafted request that bypasses the missing CSRF validation. Because the attack vector is web‑based and depends on user interaction, the operational risk remains low to moderate unless the site hosts high‑value form data.

Generated by OpenCVE AI on May 1, 2026 at 03:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Integration for Google Sheets and Contact Form 7 plugin to a version newer than 1.0.9.
  • If an update is not immediately possible, temporarily disable or remove the plugin’s integration modules until a patched version is available.
  • Add a web‑application firewall rule or implement nonce/CSRF token validation on the affected forms to block unauthorized cross‑site requests.

Generated by OpenCVE AI on May 1, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-8339 Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms allows Cross Site Request Forgery. This issue affects Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.0.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms allows Cross Site Request Forgery. This issue affects Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.0.9. Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms integration-for-contact-form-7-and-google-sheets allows Cross Site Request Forgery.This issue affects Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through <= 1.0.9.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Thu, 27 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms allows Cross Site Request Forgery. This issue affects Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.0.9.
Title WordPress Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin <= 1.0.9 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:59.168Z

Reserved: 2025-03-26T09:21:08.358Z

Link: CVE-2025-30863

cve-icon Vulnrichment

Updated: 2025-03-27T13:58:00.799Z

cve-icon NVD

Status : Deferred

Published: 2025-03-27T11:15:47.410

Modified: 2026-04-23T15:27:13.000

Link: CVE-2025-30863

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T04:00:06Z

Weaknesses