
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-9543 is a Stored Cross-Site Scripting (XSS) vulnerability in the FlexTable Google Sheets Connector WordPress plugin (also known as sheets-to-wp-table-live-sync) affecting all versions before 3.19.2. The plugin fails to sanitize and escape links imported from Google Sheet cells, enabling high-privilege users (admin or above) to inject and store malicious JavaScript — even when the unfiltered_html capability is disallowed, such as in WordPress multisite configurations. It was publicly disclosed on December 15, 2025, and assigned a CVSS v3.1 base score of 3.5 (Low) (WPScan, Red Hat CVE).
The root cause is improper neutralization of user-controlled input in web page output (CWE-79). When the "Import links from sheet" feature is enabled, the plugin fetches cell values from a linked Google Sheet and renders them as hyperlinks without sanitizing or escaping the URL content. An attacker with admin-level access can craft a Google Sheet cell containing a JavaScript payload (e.g., https://example.com?s=alert('XSS')) and link it to a plugin table; when a page embedding the table shortcode is visited by any user, the payload executes in their browser context. A verified proof-of-concept is publicly available via WPScan (WPScan).
Successful exploitation allows a malicious admin to persistently inject JavaScript that executes in the browsers of any visitor to affected pages, impacting confidentiality (e.g., session cookie theft) and integrity (e.g., page content manipulation). The vulnerability is particularly relevant in WordPress multisite environments where the unfiltered_html capability is intentionally restricted to limit admin power, as this bypass undermines that security control. Availability is not directly impacted (WPScan, Red Hat CVE).
A public proof-of-concept is available through WPScan, discovered and submitted by researcher Nguyễn Phước Thiện. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.029% (0.000290), indicating a very low probability of exploitation in the near term. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (WPScan).
https://example.com?s=alert('XSS').https://docs.google.com/spreadsheets/xxxxxx/edit?gid=0#gid=0).wp_options or plugin-specific tables) containing Google Sheet URLs linked to tables with the "Import links from sheet" feature enabled; presence of JavaScript payloads within stored cell link values.Update the FlexTable Google Sheets Connector plugin to version 3.19.2 or later, which includes proper sanitization and escaping of imported Google Sheet cell links. No configuration-based workaround is documented; disabling the "Import links from sheet" feature can reduce exposure until patching is possible. WordPress multisite administrators should prioritize this update given the vulnerability's ability to bypass the unfiltered_html capability restriction (WPScan).
The vulnerability was reported and verified by WPScan, with the original researcher credited as Nguyễn Phước Thiện. Coverage has been limited to vulnerability aggregators and security databases including Red Hat CVE, INCIBE-CERT, and CIRCL Vulnerability Lookup, reflecting the low severity rating. No notable vendor statements beyond the patch release or significant social media discussion have been identified (WPScan, Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."