Medium severity4.3NVD Advisory· Published Mar 5, 2025· Updated Apr 15, 2026
CVE-2025-1463
CVE-2025-1463
Description
The Spreadsheet Integration plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.2. This is due to improper nonce validation within the class-wpgsi-show.php script. This makes it possible for unauthenticated attackers to publish arbitrary posts, including private, granted they can trick a site administrator into performing an action such as clicking on a link.
Affected products
1- Package: https://wordpress.org/plugins/wpgsi
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.