Input validation vulnerability in WPForms Google Sheet Connector 3.4.5

The WPForms Google Sheet Connector plugin for WordPress is vulnerable to a security issue called Reflected Cross-Site Scripting in versions up to 3.4.5. This means that it is possible for someone who is not authenticated (has not logged in) to inject malicious code into pages of the website if they can get a user to click on a link. This is possible due to inadequate input sanitization and output escaping.

Detected in:

GSheetConnector For WPForms fixed vulnerable versions:
WPForms Google Sheet Connector fixed vulnerable versions: >= * <= 3.4.5
WPForms Google Sheet Connector Pro fixed vulnerable versions: >= * < 2.5.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.