Plugin Vulnerability Hub
Plugin 8 known issues Latest disclosed Mar 03, 2025

AFI – The Easiest Integration Plugin Vulnerabilities

Review known vulnerability records for the WordPress plugin AFI – The Easiest Integration Plugin (`advanced-form-integration`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2024-13123, CVE-2024-13122 and CVE-2024-56293, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
8
High or Critical
0
Patch Coverage
100%
Last Updated
Apr 21, 2025
Priority CVE Quick Links

Fast paths into AFI – The Easiest Integration Plugin CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
8
CVE-2023-50853 Medium 1.76.0
CVE-2023-50853 AFI – The Easiest Integration Plugin SQL Injection

Advanced Form Integration <= 1.75.0 - Authenticated(Administrator+) SQL Injection

CVE-2024-10877 Medium 1.92.1
CVE-2024-10877 AFI – The Easiest Integration Plugin Cross-Site Scripting

AFI – The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting

CVE-2024-2387 Medium 1.82.6
CVE-2024-2387 AFI – The Easiest Integration Plugin SQL Injection

Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id

CVE-2024-13123 Medium 1.100.0
CVE-2024-13123 AFI – The Easiest Integration Plugin Stored Cross-Site Scripting

AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting

CVE-2024-13122 Medium 1.100.0
CVE-2024-13122 AFI – The Easiest Integration Plugin Stored Cross-Site Scripting

AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting

CVE-2024-56293 Medium 1.97.0
CVE-2024-56293 AFI – The Easiest Integration Plugin Stored Cross-Site Scripting

Advanced Form Integration <= 1.95.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

CVE-2022-47173 Medium 1.63.0
CVE-2022-47173 AFI – The Easiest Integration Plugin Stored Cross-Site Scripting

Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration <= 1.62.0 - Authenticated (Admin+) Cross Site Scripting

CVE-2024-43340 Medium 1.89.6
CVE-2024-43340 AFI – The Easiest Integration Plugin Cross-Site Request Forgery

AFI – The Easiest Integration Plugin <= 1.89.4 - Cross-Site Request Forgery

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for AFI – The Easiest Integration Plugin so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
8 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 0 high severity findings.
Recent CVEs
CVE-2024-13123, CVE-2024-13122 and CVE-2024-56293
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for AFI – The Easiest Integration Plugin

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2024-13123
CVE-2024-13123: AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.99.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...

Published
Mar 03, 2025
Patched Release
1.100.0
Affected Versions
Versions up to 1.99.0
Next Step
Update to 1.100.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-13122
CVE-2024-13122: AFI – The Easiest Integration Plugin <= 1.99.0 - Authenticated (Admin+) Stored Cross-Site Scripting

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.99.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...

Published
Mar 03, 2025
Patched Release
1.100.0
Affected Versions
Versions up to 1.99.0
Next Step
Update to 1.100.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-56293
CVE-2024-56293: Advanced Form Integration <= 1.95.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.95.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access...

Published
Jan 03, 2025
Patched Release
1.97.0
Affected Versions
Versions up to 1.95.0
Next Step
Update to 1.97.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10877
CVE-2024-10877: AFI – The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.92.0. This makes it possible for unauth...

Published
Nov 12, 2024
Patched Release
1.92.1
Affected Versions
Versions up to 1.92.0
Next Step
Update to 1.92.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-43340
CVE-2024-43340: AFI – The Easiest Integration Plugin <= 1.89.4 - Cross-Site Request Forgery

The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.89.4. This is due to missing or incorrect nonce validation on the adfoin_duplicate_integration() function. This makes it possible for unau...

Published
Aug 16, 2024
Patched Release
1.89.6
Affected Versions
Versions up to 1.89.4
Next Step
Update to 1.89.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2387
CVE-2024-2387: Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user...

Published
Mar 19, 2024
Patched Release
1.82.6
Affected Versions
Versions up to 1.82.0
Next Step
Update to 1.82.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-50853
CVE-2023-50853: Advanced Form Integration <= 1.75.0 - Authenticated(Administrator+) SQL Injection

The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.76.0 (exclusive) due to insufficient escaping on the user supplied para...

Published
Dec 21, 2023
Patched Release
1.76.0
Affected Versions
Versions before 1.76.0
Next Step
Update to 1.76.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-47173
CVE-2022-47173: Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration <= 1.62.0 - Authenticated (Admin+) Cross Site Scripting

The Connect Contact Form 7, WooCommerce To Google Sheets & Other Platforms – Advanced Form Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.62.0 due to insufficient input sanitization and output e...

Published
Jan 27, 2023
Patched Release
1.63.0
Affected Versions
Versions up to 1.62.0
Next Step
Update to 1.63.0 or newer if supported.