Impact
The WPForms Google Sheet Connector plugin by WesternDeal has a critical Code Injection flaw (CWE‑94) that allows an attacker to inject and execute arbitrary code within the WordPress environment. An attacker could trigger this by supplying crafted input that the plugin processes, leading to full control over the server or application. The vulnerability can compromise confidentiality, integrity, and availability, granting attackers the ability to install malware, exfiltrate data, or disrupt services.
Affected Systems
All installations using WesternDeal WPForms Google Sheet Connector plugin version 4.0.1 or earlier are affected. The issue spans from the earliest releases up to and including version 4.0.1.
Risk and Exploitability
The flaw has a CVSS score of 9.9, indicating critical severity. The EPSS score is below 1 %, suggesting that, while the vulnerability is severe, the likelihood of exploitation is currently very low. The problem is not listed in the CISA KEV catalog. Likely exploitation would require that the plugin is active in a public or unprotected WordPress site and that attacker‑controlled input reaches the vulnerable code path. No public exploit is currently documented.
OpenCVE Enrichment