Input validation vulnerability in Elementor Forms Google Sheet Connector Pro 1.0.6

The Elementor Forms Google Sheet Connector plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This attack can be done with versions up to and including 1.0.6. It happens because the plugin does not properly sanitize the user input and the output is not properly escaped. This means that an attacker can inject malicious code into pages that will be executed when a user is tricked into clicking on a link.

Detected in:

Elementor Forms Google Sheet Connector fixed vulnerable versions: >= * <= 1.0.6
Elementor Forms Google Sheet Connector Pro open vulnerable versions: >= * <= 1.0.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.