CVE-2025-8593: GSheetConnector For Gravity Forms <= 1.3.27 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, or equal to, 1.3.27. This is due to a missing capability check on the 'installplugin' function. This makes it possible for authenticated attackers, with subscriber-level access and above to install plugins on the target site and potentially achieve arbitrary code execution on the server under certain conditions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8593?
CVE-2025-8593 has a medium severity rating due to the potential for unauthorized access by authenticated attackers.
How do I fix CVE-2025-8593?
To fix CVE-2025-8593, update the GSheetConnector for Gravity Forms plugin to version 1.3.28 or later.
Who is affected by CVE-2025-8593?
Users of the GSheetConnector For Gravity Forms plugin for WordPress running versions 1.3.27 or earlier are affected by CVE-2025-8593.
What type of vulnerability is CVE-2025-8593?
CVE-2025-8593 is an authorization bypass vulnerability.
What causes the vulnerability in CVE-2025-8593?
The vulnerability is caused by a missing capability check in the 'install_plugin' function of the GSheetConnector for Gravity Forms.