---
id: CVE-2025-8606
title: >-
  The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to
  Cross-Site Request Forgery in versions less than, or equal to, 1.3.23
summary: >-
  The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to
  Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is
  due to missing or incorrect nonce validation on the activate_plugin and
  deactivate…
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-352
published: '2025-10-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8606'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/gsheetconnector-gravity-forms/tags/1.3.23/includes/class-gravityform-gs-service.php#L154
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/gsheetconnector-gravity-forms/tags/1.3.23/includes/class-gravityform-gs-service.php#L39
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3339653'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/d5c48de7-20f6-408e-b4fb-f3d5d7ab272f?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00155
epssPercentile: 0.0404
ingestedAt: '2026-10-08T13:42:55.108Z'
---

## Overview

The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is due to missing or incorrect nonce validation on the activate_plugin and deactivate_plugin functions. This makes it possible for attackers to trick authenticated administrators into activating or deactivating specified plugins via a forged request, such as clicking on a malicious link or visiting a compromised page.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
