CVE-2025-8606EPSS p4.1%
CVE-2025-8606CVE-2025-8606
Description
The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 1.3.23. This is due to missing or incorrect nonce validation on the activate_plugin and deactivate_plugin functions. This makes it possible for attackers to trick authenticated administrators into activating or deactivating specified plugins via a forged request, such as clicking on a malicious link or visiting a compromised page.
Scoring
| CVSS | 2.4 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N |
| EPSS | 0.15% probability of exploitation · percentile 4.1% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |