Impact
The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to forge requests to the WordPress site and cause the Connector for Gravity Forms and Google Sheets plugin to perform actions without the user’s explicit consent. An exploitable request can trigger the creation, modification, or deletion of spreadsheet entries, potentially exposing or corrupting sensitive data. The flaw represents a moderate risk to data integrity and confidentiality.
Affected Systems
Users of the CRM Perks Connector for Gravity Forms and Google Sheets plugin on WordPress sites are affected when running version 1.2.4 or earlier.
Risk and Exploitability
The CVSS score of 5.4 classifies the flaw as moderate, and the EPSS score of less than 1% indicates a very low stated probability of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. The attack vector likely involves an authenticated user whose session is hijacked or a malicious site that forces a victim’s browser to submit a forged request. While the plugin’s documentation does not specify required privileges, the CSRF mechanism typically requires the attacker to convince a user with sufficient access rights to visit a crafted URL or click a link.
OpenCVE Enrichment
EUVD