First published: Thu Mar 27 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms allows Cross Site Request Forgery. This issue affects Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms: from n/a through 1.0.9.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CRM Perks Integration for Google Sheets and Contact Form 7 | <=1.0.9 | |
WPForms | <=1.0.9 | |
CRM Perks Elementor | <=1.0.9 | |
CRM Perks Ninja Forms | <=1.0.9 |
Update the WordPress Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms plugin to the latest available version (at least 1.1.0).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30863 is considered a moderate severity vulnerability due to its Cross-Site Request Forgery (CSRF) nature.
To fix CVE-2025-30863, update the affected CRM Perks Integration for Google Sheets and associated plugins to the latest versions beyond 1.0.9.
CVE-2025-30863 affects the CRM Perks Integration for Google Sheets, WPForms, Elementor, and Ninja Forms versions up to and including 1.0.9.
An attacker exploiting CVE-2025-30863 could potentially perform unauthorized actions on behalf of a user without their consent.
Yes, CVE-2025-30863 is a documented vulnerability that has been identified in specific CRM Perks plugins.