CVE-2025-54682: WordPress Connector for Gravity Forms and Google Sheets Plugin plugin <= 1.2.4 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets allows Cross Site Request Forgery. This issue affects Connector for Gravity Forms and Google Sheets: from n/a through 1.2.4.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Cross Site Request Forgery.This issue affects Connector for Gravity Forms and Google Sheets: from n/a through <= 1.2.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54682?
The severity of CVE-2025-54682 is classified as critical due to its potential to allow unauthorized actions via Cross-Site Request Forgery.
How do I fix CVE-2025-54682?
To fix CVE-2025-54682, update the CRM Perks Connector for Gravity Forms and Google Sheets to version 1.2.5 or later.
What versions are affected by CVE-2025-54682?
CVE-2025-54682 affects versions of the Connector for Gravity Forms and Google Sheets up to and including version 1.2.4.
What type of vulnerability is CVE-2025-54682?
CVE-2025-54682 is a Cross-Site Request Forgery (CSRF) vulnerability.
Who is the vendor for CVE-2025-54682?
The vendor for CVE-2025-54682 is CRM Perks.