Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function
medium
The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with sub...
- CVSS:
- 4.3
- Affected:
- up to 2.6.0
- Fixed in:
- 2.7.0
- Disclosed:
- Jul 27, 2026
CVE-2026-16587 on NVD →
Advanced Form Integration <= 2.1.0 - Unauthenticated Privilege Escalation
high
The Advanced Form Integration plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.1.0. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privileges beyond those intende...
- CVSS:
- 8.1
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Jun 10, 2026
CVE-2026-11794 on NVD →
AFI – The Easiest Integration Plugin <= 1.126.12 - Missing Authorization
medium
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.126.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.126.12
- Fixed in:
- 1.127.0
- Disclosed:
- Apr 29, 2026
CVE-2026-42659 on NVD →
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.100.0
unknown
[en] The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.100.0
- Fixed in:
- 1.100.0
- Disclosed:
- Mar 25, 2025
CVE-2024-13122 on NVD →
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.100.0
unknown
[en] The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 1.100.0
- Fixed in:
- 1.100.0
- Disclosed:
- Mar 25, 2025
CVE-2024-13123 on NVD →
AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.99.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...
- CVSS:
- 4.4
- Affected:
- up to 1.99.0
- Fixed in:
- 1.100.0
- Disclosed:
- Mar 3, 2025
CVE-2024-13123 on NVD →
AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.99.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...
- CVSS:
- 4.4
- Affected:
- up to 1.99.0
- Fixed in:
- 1.100.0
- Disclosed:
- Mar 3, 2025
CVE-2024-13122 on NVD →
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.97.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nasirahmed Advanced Form Integration allows Stored XSS.This issue affects Advanced Form Integration: from n/a through 1.95.0.
- Affected:
- up to 1.97.0
- Fixed in:
- 1.97.0
- Disclosed:
- Jan 7, 2025
CVE-2024-56293 on NVD →
Advanced Form Integration <= 1.95.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.95.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scri...
- CVSS:
- 4.4
- Affected:
- up to 1.95.0
- Fixed in:
- 1.97.0
- Disclosed:
- Jan 3, 2025
CVE-2024-56293 on NVD →
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.92.1
unknown
[en] The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.92.0. This makes it possible for unauthenticated attackers to inject arbit...
- Affected:
- up to 1.92.1
- Fixed in:
- 1.92.1
- Disclosed:
- Nov 13, 2024
CVE-2024-10877 on NVD →
AFI – The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting
medium
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.92.0. This makes it possible for unauthenticated attackers to inject arbitrary...
- CVSS:
- 6.1
- Affected:
- up to 1.92.0
- Fixed in:
- 1.92.1
- Disclosed:
- Nov 12, 2024
CVE-2024-10877 on NVD →
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.49.0
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 1.49.0
- Fixed in:
- 1.49.0
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.89.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4.
- Affected:
- up to 1.89.6
- Fixed in:
- 1.89.6
- Disclosed:
- Aug 26, 2024
CVE-2024-43340 on NVD →
AFI – The Easiest Integration Plugin <= 1.89.4 - Cross-Site Request Forgery
medium
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.89.4. This is due to missing or incorrect nonce validation on the adfoin_duplicate_integration() function. This makes it possible for unauthenticated attackers to duplicate an in...
- CVSS:
- 4.3
- Affected:
- up to 1.89.4
- Fixed in:
- 1.89.6
- Disclosed:
- Aug 16, 2024
CVE-2024-43340 on NVD →
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.82.6
unknown
[en] The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user supplied parameter and lack of suf...
- Affected:
- up to 1.82.6
- Fixed in:
- 1.82.6
- Disclosed:
- Mar 20, 2024
CVE-2024-2387 on NVD →
Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id
medium
The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user supplied parameter and lack of sufficie...
- CVSS:
- 6.1
- Affected:
- up to 1.82.0
- Fixed in:
- 1.82.6
- Disclosed:
- Mar 19, 2024
CVE-2024-2387 on NVD →
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.76.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nasirahmed Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms.This issue affects Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sh...
- Affected:
- up to 1.76.0
- Fixed in:
- 1.76.0
- Disclosed:
- Dec 28, 2023
CVE-2023-50853 on NVD →
Advanced Form Integration <= 1.75.0 - Authenticated(Administrator+) SQL Injection
medium
The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.76.0 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...
- CVSS:
- 6.6
- Affected:
- up to 1.76.0
- Fixed in:
- 1.76.0
- Disclosed:
- Dec 21, 2023
CVE-2023-50853 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 1.69.0
- Fixed in:
- 1.69.1
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.63.0
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nasirahmed Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin <= 1.62.0 versions.
- Affected:
- up to 1.63.0
- Fixed in:
- 1.63.0
- Disclosed:
- Mar 23, 2023
CVE-2022-47173 on NVD →
Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration <= 1.62.0 - Authenticated (Admin+) Cross Site Scripting
medium
The Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.62.0 due to insufficient input sanitization and output escaping. This makes it possible for auth...
- CVSS:
- 4.4
- Affected:
- up to 1.62.0
- Fixed in:
- 1.63.0
- Disclosed:
- Jan 27, 2023
CVE-2022-47173 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 1.49.0
- Fixed in:
- 1.49.0
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.49.0
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 1.49.0
- Fixed in:
- 1.49.0
- Disclosed:
- Mar 4, 2022
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.49.0
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress "Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration" plugin (versions < 1.49.0).
- Affected:
- up to 1.49.0
- Fixed in:
- 1.49.0
- Disclosed:
- Feb 28, 2022
AFI – The Easiest Integration Plugin [advanced-form-integration] < 1.69.1
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.69.1
- Fixed in:
- 1.69.1
CVE-2023-33999 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database