CVE-2025-13136: GSheetConnector For Ninja Forms <= 2.0.1 - Missing Authorization to Authenticated (Subscriber+) System Information Exposure
The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'njform-google-sheet-config ' page in all versions up to, and including, 2.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to retrieve information about the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13136?
CVE-2025-13136 has a high severity due to the potential for unauthorized access to sensitive data.
How do I fix CVE-2025-13136?
To fix CVE-2025-13136, update the GSheetConnector For Ninja Forms plugin to version 2.0.2 or later.
Who is affected by CVE-2025-13136?
Users of the GSheetConnector For Ninja Forms plugin for WordPress running versions up to and including 2.0.1 are affected by CVE-2025-13136.
What kind of access does CVE-2025-13136 allow?
CVE-2025-13136 allows authenticated attackers to access configuration data without proper authorization.
Is there a patch available for CVE-2025-13136?
Yes, a patch is available in the form of an update to version 2.0.2 or later of the plugin.