plugin

Integromat Connector Vulnerabilities

6 known security issues reported for the Integromat Connector WordPress plugin. Most recent disclosed Sep 3, 2025.

2 high 1 medium

Running Integromat Connector on your site? Check whether your installed version is affected.

Scan your site free

Make Connector <= 1.5.10 - Authenticated (Administrator+) Arbitrary File Upload

high

The Make Connector plugin for WordPress is vulnerable to arbitrary file uploads due to misconfigured file type validation in the 'upload_media' function in all versions up to, and including, 1.5.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files...

CVSS:
7.2
Affected:
up to 1.5.10
Fixed in:
1.6.0
Disclosed:
Sep 3, 2025

CVE-2025-6085 on NVD →

Make, formerly Integromat Connector <= 1.5.2 - Authenticated (Subscriber+) Information Disclosure

medium

The Make plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce verification on an admin_menu action in versions up to, and including, 1.5.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the plugin's logs whi...

CVSS:
6.5
Affected:
up to 1.5.2
Fixed in:
1.5.3
Disclosed:
Sep 26, 2022

Make Connector [integromat-connector] < 1.5.3 (closed)

unknown

The Make plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce verification on an admin_menu action in versions up to, and including, 1.5.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the plugin's logs whi...

Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Sep 26, 2022

Make, formerly Integromat Connector <= 1.5.1 - Missing Authorization to Arbitrary Options Update

high

The Make, formerly Integromat Connector plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 1.5.1 due to missing authorization checks on the function called via 'admin_menu' in addition to insufficient option validation. This makes it possible for authenticated attackers wi...

CVSS:
8.8
Affected:
up to 1.5.1
Fixed in:
1.5.2
Disclosed:
Aug 17, 2022

Make Connector [integromat-connector] < 1.5.2 (closed)

unknown

The Make, formerly Integromat Connector plugin for WordPress is vulnerable to arbitrary options updates in versions up to, and including, 1.5.1 due to missing authorization checks on the function called via 'admin_menu' in addition to insufficient option validation. This makes it possible for authenticated attackers wi...

Affected:
up to 1.5.2
Fixed in:
1.5.2
Disclosed:
Aug 17, 2022

Make Connector [integromat-connector] <= 1.5.10 (unfixed)

unknown
Affected:
up to 1.5.10
Fix:
No patched version reported

CVE-2025-6085 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database