plugin

Advanced Form Integration Vulnerabilities

25 known security issues reported for the Advanced Form Integration WordPress plugin. Most recent disclosed Jul 27, 2026.

1 high 12 medium

Running Advanced Form Integration on your site? Check whether your installed version is affected.

Scan your site free

Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function

medium

The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with sub...

CVSS:
4.3
Affected:
up to 2.6.0
Fixed in:
2.7.0
Disclosed:
Jul 27, 2026

CVE-2026-16587 on NVD →

Advanced Form Integration <= 2.1.0 - Unauthenticated Privilege Escalation

high

The Advanced Form Integration plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.1.0. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privileges beyond those intende...

CVSS:
8.1
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Jun 10, 2026

CVE-2026-11794 on NVD →

AFI – The Easiest Integration Plugin <= 1.126.12 - Missing Authorization

medium

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.126.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.126.12
Fixed in:
1.127.0
Disclosed:
Apr 29, 2026

CVE-2026-42659 on NVD →

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.100.0

unknown

[en] The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 1.100.0
Fixed in:
1.100.0
Disclosed:
Mar 25, 2025

CVE-2024-13122 on NVD →

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.100.0

unknown

[en] The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Affected:
up to 1.100.0
Fixed in:
1.100.0
Disclosed:
Mar 25, 2025

CVE-2024-13123 on NVD →

AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.99.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...

CVSS:
4.4
Affected:
up to 1.99.0
Fixed in:
1.100.0
Disclosed:
Mar 3, 2025

CVE-2024-13123 on NVD →

AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.99.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...

CVSS:
4.4
Affected:
up to 1.99.0
Fixed in:
1.100.0
Disclosed:
Mar 3, 2025

CVE-2024-13122 on NVD →

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.97.0

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nasirahmed Advanced Form Integration allows Stored XSS.This issue affects Advanced Form Integration: from n/a through 1.95.0.

Affected:
up to 1.97.0
Fixed in:
1.97.0
Disclosed:
Jan 7, 2025

CVE-2024-56293 on NVD →

Advanced Form Integration <= 1.95.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.95.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scri...

CVSS:
4.4
Affected:
up to 1.95.0
Fixed in:
1.97.0
Disclosed:
Jan 3, 2025

CVE-2024-56293 on NVD →

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.92.1

unknown

[en] The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.92.0. This makes it possible for unauthenticated attackers to inject arbit...

Affected:
up to 1.92.1
Fixed in:
1.92.1
Disclosed:
Nov 13, 2024

CVE-2024-10877 on NVD →

AFI – The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting

medium

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.92.0. This makes it possible for unauthenticated attackers to inject arbitrary...

CVSS:
6.1
Affected:
up to 1.92.0
Fixed in:
1.92.1
Disclosed:
Nov 12, 2024

CVE-2024-10877 on NVD →

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.49.0

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 1.49.0
Fixed in:
1.49.0
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.89.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4.

Affected:
up to 1.89.6
Fixed in:
1.89.6
Disclosed:
Aug 26, 2024

CVE-2024-43340 on NVD →

AFI – The Easiest Integration Plugin <= 1.89.4 - Cross-Site Request Forgery

medium

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.89.4. This is due to missing or incorrect nonce validation on the adfoin_duplicate_integration() function. This makes it possible for unauthenticated attackers to duplicate an in...

CVSS:
4.3
Affected:
up to 1.89.4
Fixed in:
1.89.6
Disclosed:
Aug 16, 2024

CVE-2024-43340 on NVD →

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.82.6

unknown

[en] The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user supplied parameter and lack of suf...

Affected:
up to 1.82.6
Fixed in:
1.82.6
Disclosed:
Mar 20, 2024

CVE-2024-2387 on NVD →

Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id

medium

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user supplied parameter and lack of sufficie...

CVSS:
6.1
Affected:
up to 1.82.0
Fixed in:
1.82.6
Disclosed:
Mar 19, 2024

CVE-2024-2387 on NVD →

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.76.0

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nasirahmed Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms.This issue affects Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sh...

Affected:
up to 1.76.0
Fixed in:
1.76.0
Disclosed:
Dec 28, 2023

CVE-2023-50853 on NVD →

Advanced Form Integration <= 1.75.0 - Authenticated(Administrator+) SQL Injection

medium

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.76.0 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

CVSS:
6.6
Affected:
up to 1.76.0
Fixed in:
1.76.0
Disclosed:
Dec 21, 2023

CVE-2023-50853 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 1.69.0
Fixed in:
1.69.1
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.63.0

unknown

[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in nasirahmed Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin <= 1.62.0 versions.

Affected:
up to 1.63.0
Fixed in:
1.63.0
Disclosed:
Mar 23, 2023

CVE-2022-47173 on NVD →

Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration <= 1.62.0 - Authenticated (Admin+) Cross Site Scripting

medium

The Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.62.0 due to insufficient input sanitization and output escaping. This makes it possible for auth...

CVSS:
4.4
Affected:
up to 1.62.0
Fixed in:
1.63.0
Disclosed:
Jan 27, 2023

CVE-2022-47173 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 1.49.0
Fixed in:
1.49.0
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.49.0

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 1.49.0
Fixed in:
1.49.0
Disclosed:
Mar 4, 2022

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.49.0

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress "Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration" plugin (versions < 1.49.0).

Affected:
up to 1.49.0
Fixed in:
1.49.0
Disclosed:
Feb 28, 2022

AFI &#8211; The Easiest Integration Plugin [advanced-form-integration] < 1.69.1

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.69.1
Fixed in:
1.69.1

CVE-2023-33999 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database