plugin

Integrate Google Drive Vulnerabilities

30 known security issues reported for the Integrate Google Drive WordPress plugin. Most recent disclosed Apr 30, 2026.

1 critical 2 high 11 medium

Running Integrate Google Drive on your site? Check whether your installed version is affected.

Scan your site free

Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter

medium

Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 1.4.9
Fixed in:
1.5.0
Disclosed:
Apr 30, 2026

CVE-2024-13362 on NVD →

Integrate Google Drive <= 1.5.6 - Missing Authorization

medium

The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 1.5.6
Fix:
No patched version reported
Disclosed:
Jan 24, 2026

CVE-2026-24540 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] <= 1.5.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in Prince Integrate Google Drive integrate-google-drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through <= 1.5.5.

Affected:
up to 1.5.5
Fix:
No patched version reported
Disclosed:
Jan 23, 2026

CVE-2026-24540 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.5.4

unknown

[en] The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including G...

Affected:
up to 1.5.4
Fixed in:
1.5.4
Disclosed:
Nov 5, 2025

CVE-2025-12139 on NVD →

File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure

high

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including Google...

CVSS:
7.5
Affected:
up to 1.5.3
Fixed in:
1.5.4
Disclosed:
Nov 4, 2025

CVE-2025-12139 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.5.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Prince Integrate Google Drive allows Cross Site Request Forgery. This issue affects Integrate Google Drive: from n/a through 1.5.2.

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Aug 14, 2025

CVE-2025-54703 on NVD →

Integrate Google Drive <= 1.5.2 - Cross-Site Request Forgery

medium

The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an u...

CVSS:
4.3
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Jul 30, 2025

CVE-2025-54703 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.2.0

unknown

[en] Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

Affected:
up to 1.2.0
Fixed in:
1.2.0
Disclosed:
Dec 9, 2024

CVE-2023-32117 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.1.0

unknown

[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....

Affected:
up to 1.1.0
Fixed in:
1.1.0
Disclosed:
Oct 16, 2024

CVE-2022-4974 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.3.4

unknown

[en] Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3.

Affected:
up to 1.3.4
Fixed in:
1.3.4
Disclosed:
Jun 12, 2024

CVE-2023-52177 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.3.91

unknown

[en] Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.9.

Affected:
up to 1.3.91
Fixed in:
1.3.91
Disclosed:
Jun 9, 2024

CVE-2024-32813 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.3.94

unknown

[en] Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93.

Affected:
up to 1.3.94
Fixed in:
1.3.94
Disclosed:
Jun 4, 2024

CVE-2024-35670 on NVD →

Integrate Google Drive <= 1.3.93 - Missing Authorization

medium

The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.93. This makes it possible f...

CVSS:
5.3
Affected:
up to 1.3.93
Fixed in:
1.3.94
Disclosed:
Jun 3, 2024

CVE-2024-35670 on NVD →

Integrate Google Drive <= 1.3.9 - Missing Authorization

medium

The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in versions up to, and including, 1.3.9. This makes it possible for unauthenticated attackers to perform unauthorized actions.

CVSS:
6.5
Affected:
up to 1.3.9
Fixed in:
1.3.91
Disclosed:
Apr 22, 2024

CVE-2024-32813 on NVD →

Integrate Google Drive <= 1.3.8 - Missing Authorization

medium

The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 1.3.8. This makes it possible for unauthenticated attackers to perform unauthorized actions.

CVSS:
5.3
Affected:
up to 1.3.8
Fixed in:
1.3.91
Disclosed:
Apr 22, 2024

CVE-2024-32949 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.3.9

unknown

[en] The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all version...

Affected:
up to 1.3.9
Fixed in:
1.3.9
Disclosed:
Mar 30, 2024

CVE-2024-2086 on NVD →

Integrate Google Drive <= 1.3.8 - Missing Authorization to Unauthenticated Settings Modification and Export

critical

The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up...

CVSS:
10
Affected:
up to 1.3.8
Fixed in:
1.3.9
Disclosed:
Mar 29, 2024

CVE-2024-2086 on NVD →

Integrate Google Drive <= 1.3.3 - Missing Authorization via save_settings

medium

The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the plugin's s...

CVSS:
4.3
Affected:
up to 1.3.3
Fixed in:
1.3.4
Disclosed:
Dec 29, 2023

CVE-2023-52177 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.3.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.4.

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Dec 17, 2023

CVE-2023-49769 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.3.3

unknown

[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery,...

Affected:
up to 1.3.3
Fixed in:
1.3.3
Disclosed:
Dec 7, 2023

CVE-2023-47548 on NVD →

Integrate Google Drive <= 1.3.4 - Cross-Site Request Forgery

medium

The Integrate Google Drive plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request gr...

CVSS:
4.3
Affected:
up to 1.3.4
Fixed in:
1.3.5
Disclosed:
Dec 5, 2023

CVE-2023-49769 on NVD →

Integrate Google Drive <= 1.3.2 - Open Redirect via state

medium

The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.2. This is due to insufficient validation on the redirect url supplied via the 'st...

CVSS:
4.7
Affected:
up to 1.3.2
Fixed in:
1.3.3
Disclosed:
Nov 7, 2023

CVE-2023-47548 on NVD →

Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get

medium

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
1.0.0 – 1.2.1
Fixed in:
1.2.2
Disclosed:
Jul 18, 2023

CVE-2023-33999 on NVD →

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

high

The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in versions up to, and including, 1.1.99. This makes it possible for unauthenticated attackers to perform a wide variety of operations, such as moving files, creating fold...

CVSS:
7.3
Affected:
up to 1.1.99
Fixed in:
1.2.0
Disclosed:
Jul 12, 2023

CVE-2023-32117 on NVD →

Freemius SDK <= 2.4.2 - Missing Authorization Checks

medium

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

CVSS:
6.3
Affected:
up to 1.1.0
Fixed in:
1.1.0
Disclosed:
Mar 4, 2022

CVE-2022-4974 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.1.0

unknown

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...

Affected:
up to 1.1.0
Fixed in:
1.1.0
Disclosed:
Mar 4, 2022

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.1.0

unknown

Sensitive Information Disclosure vulnerability discovered in WordPress Integrate Google Drive – Complete Google Drive Cloud Solution For WordPress plugin (versions < 1.1.0).

Affected:
up to 1.1.0
Fixed in:
1.1.0
Disclosed:
Feb 28, 2022

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.1.0

unknown

Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Integrate Google Drive – Complete Google Drive Cloud Solution For WordPress plugin (versions < 1.1.0).

Affected:
up to 1.1.0
Fixed in:
1.1.0
Disclosed:
Feb 28, 2022

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.2.3

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 1.2.3
Fixed in:
1.2.3

CVE-2023-33999 on NVD →

File Manager for Google Drive &#8211; Integrate Google Drive [integrate-google-drive] < 1.3.91

unknown
Affected:
up to 1.3.91
Fixed in:
1.3.91

CVE-2024-32949 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database