WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in WPGSI: Spreadsheet Integration

Google sheet two-way sync 🔄 WordPress | WooCommerce | Contact form 7 | DB table | Google sheet as a Table.

5Reported vulnerabilities
8.8Highest CVSS score
3.8.4Latest version
2,000+Active installs

What to do now

Update WPGSI: Spreadsheet Integration to 3.8.4 or later. 5 of these have a fixed version available. Updating resolves them.

Plugin last updated: February 14, 2026 / Tested up to WordPress: 6.9.7 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
WF-6a3dddda-3a65-42b6-9dc8-760bc3a24dcf High 8.8 — 3.5.0 and earlier 3.6.0 December 24, 2021
CVE-2026-1916 High 7.5 0.4% 0 to 3.8.3 (inclusive) 3.8.4 February 25, 2026
WF-014da588-9494-493e-8659-590b8e8c14a6 Medium 6.1 — 3.5.0 and earlier 3.6.0 December 24, 2021
CVE-2025-1463 Medium 4.3 0.2% 0 to 3.8.2 (inclusive) 3.8.3 March 5, 2025
CVE-2024-6590 Medium 4.3 0.3% 3.7.9 and earlier 3.8.1 September 25, 2024

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.