Freemius <= 2.10.1 - Reflected DOM-Based Cross-Site Scripting via url Parameter
medium
Multiple plugins and/or themes for WordPress are vulnerable to Reflected Cross-Site Scripting via the url parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 1.4.9
- Fixed in:
- 1.5.0
- Disclosed:
- Apr 30, 2026
CVE-2024-13362 on NVD →
Integrate Google Drive <= 1.5.6 - Missing Authorization
medium
The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 1.5.6
- Fix:
- No patched version reported
- Disclosed:
- Jan 24, 2026
CVE-2026-24540 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] <= 1.5.5 (unfixed)
unknown
[en] Missing Authorization vulnerability in Prince Integrate Google Drive integrate-google-drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through <= 1.5.5.
- Affected:
- up to 1.5.5
- Fix:
- No patched version reported
- Disclosed:
- Jan 23, 2026
CVE-2026-24540 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.5.4
unknown
[en] The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including G...
- Affected:
- up to 1.5.4
- Fixed in:
- 1.5.4
- Disclosed:
- Nov 5, 2025
CVE-2025-12139 on NVD →
File Manager for Google Drive – Integrate Google Drive with WordPress <= 1.5.3 - Unauthenticated Sensitive Information Exposure
high
The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including Google...
- CVSS:
- 7.5
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.4
- Disclosed:
- Nov 4, 2025
CVE-2025-12139 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.5.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Prince Integrate Google Drive allows Cross Site Request Forgery. This issue affects Integrate Google Drive: from n/a through 1.5.2.
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Aug 14, 2025
CVE-2025-54703 on NVD →
Integrate Google Drive <= 1.5.2 - Cross-Site Request Forgery
medium
The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an u...
- CVSS:
- 4.3
- Affected:
- up to 1.5.2
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 30, 2025
CVE-2025-54703 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.2.0
unknown
[en] Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.
- Affected:
- up to 1.2.0
- Fixed in:
- 1.2.0
- Disclosed:
- Dec 9, 2024
CVE-2023-32117 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.1.0
unknown
[en] The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4....
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.0
- Disclosed:
- Oct 16, 2024
CVE-2022-4974 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.3.4
unknown
[en] Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3.
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.4
- Disclosed:
- Jun 12, 2024
CVE-2023-52177 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.3.91
unknown
[en] Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.9.
- Affected:
- up to 1.3.91
- Fixed in:
- 1.3.91
- Disclosed:
- Jun 9, 2024
CVE-2024-32813 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.3.94
unknown
[en] Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93.
- Affected:
- up to 1.3.94
- Fixed in:
- 1.3.94
- Disclosed:
- Jun 4, 2024
CVE-2024-35670 on NVD →
Integrate Google Drive <= 1.3.93 - Missing Authorization
medium
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.3.93. This makes it possible f...
- CVSS:
- 5.3
- Affected:
- up to 1.3.93
- Fixed in:
- 1.3.94
- Disclosed:
- Jun 3, 2024
CVE-2024-35670 on NVD →
Integrate Google Drive <= 1.3.9 - Missing Authorization
medium
The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several functions in versions up to, and including, 1.3.9. This makes it possible for unauthenticated attackers to perform unauthorized actions.
- CVSS:
- 6.5
- Affected:
- up to 1.3.9
- Fixed in:
- 1.3.91
- Disclosed:
- Apr 22, 2024
CVE-2024-32813 on NVD →
Integrate Google Drive <= 1.3.8 - Missing Authorization
medium
The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 1.3.8. This makes it possible for unauthenticated attackers to perform unauthorized actions.
- CVSS:
- 5.3
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.91
- Disclosed:
- Apr 22, 2024
CVE-2024-32949 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.3.9
unknown
[en] The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all version...
- Affected:
- up to 1.3.9
- Fixed in:
- 1.3.9
- Disclosed:
- Mar 30, 2024
CVE-2024-2086 on NVD →
Integrate Google Drive <= 1.3.8 - Missing Authorization to Unauthenticated Settings Modification and Export
critical
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up...
- CVSS:
- 10
- Affected:
- up to 1.3.8
- Fixed in:
- 1.3.9
- Disclosed:
- Mar 29, 2024
CVE-2024-2086 on NVD →
Integrate Google Drive <= 1.3.3 - Missing Authorization via save_settings
medium
The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the plugin's s...
- CVSS:
- 4.3
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.4
- Disclosed:
- Dec 29, 2023
CVE-2023-52177 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.3.5
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.4.
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Dec 17, 2023
CVE-2023-49769 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.3.3
unknown
[en] URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery,...
- Affected:
- up to 1.3.3
- Fixed in:
- 1.3.3
- Disclosed:
- Dec 7, 2023
CVE-2023-47548 on NVD →
Integrate Google Drive <= 1.3.4 - Cross-Site Request Forgery
medium
The Integrate Google Drive plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.4. This is due to missing or incorrect nonce validation on an unknown function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request gr...
- CVSS:
- 4.3
- Affected:
- up to 1.3.4
- Fixed in:
- 1.3.5
- Disclosed:
- Dec 5, 2023
CVE-2023-49769 on NVD →
Integrate Google Drive <= 1.3.2 - Open Redirect via state
medium
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.3.2. This is due to insufficient validation on the redirect url supplied via the 'st...
- CVSS:
- 4.7
- Affected:
- up to 1.3.2
- Fixed in:
- 1.3.3
- Disclosed:
- Nov 7, 2023
CVE-2023-47548 on NVD →
Freemius SDK <= 2.5.9 - Reflected Cross-Site Scripting via fs_request_get
medium
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- 1.0.0 – 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Jul 18, 2023
CVE-2023-33999 on NVD →
Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints
high
The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in versions up to, and including, 1.1.99. This makes it possible for unauthenticated attackers to perform a wide variety of operations, such as moving files, creating fold...
- CVSS:
- 7.3
- Affected:
- up to 1.1.99
- Fixed in:
- 1.2.0
- Disclosed:
- Jul 12, 2023
CVE-2023-32117 on NVD →
Freemius SDK <= 2.4.2 - Missing Authorization Checks
medium
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- CVSS:
- 6.3
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.0
- Disclosed:
- Mar 4, 2022
CVE-2022-4974 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.1.0
unknown
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. An...
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.0
- Disclosed:
- Mar 4, 2022
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.1.0
unknown
Sensitive Information Disclosure vulnerability discovered in WordPress Integrate Google Drive – Complete Google Drive Cloud Solution For WordPress plugin (versions < 1.1.0).
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.0
- Disclosed:
- Feb 28, 2022
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.1.0
unknown
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Integrate Google Drive – Complete Google Drive Cloud Solution For WordPress plugin (versions < 1.1.0).
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.0
- Disclosed:
- Feb 28, 2022
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.2.3
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
CVE-2023-33999 on NVD →
File Manager for Google Drive – Integrate Google Drive [integrate-google-drive] < 1.3.91
unknown
- Affected:
- up to 1.3.91
- Fixed in:
- 1.3.91
CVE-2024-32949 on NVD →