CVE detail
CVE-2026-16614
The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 5.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. wp_unslash() strips magic-quote protection and sanitize_text_field() does not escape SQL metacharacters, leaving single quotes and other SQL metacharacters intact before the value is interpolated into the query.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (July 27, 2026 to August 2, 2026)Wordfence
uthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter 9.8 CVSS Rating 9.8 (Critical) CVE-ID CVE-2026-18072 Patch Status Unpatched Published Jul 28, 2026 Affected Software Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … [advanced-responsive-video-embedder] Researcher Wordfence PRISM More Details
vendorwww.wordfence.comAug 8, 2026, 12:26 AM - https://www.wordfence.com/threat-intel/vulnerabilities/id/83455de5-4fb2-4782-8063-646d3daf29e5?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comAug 1, 2026, 9:17 AM - https://plugins.trac.wordpress.org/changeset?reponame=&old=3628480%40cf7-google-sheets-connector&new=3628480%40cf7-google-sheets-connectorplugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 1, 2026, 9:17 AM - https://plugins.trac.wordpress.org/browser/cf7-google-sheets-connector/tags/5.1.7/includes/pages/gs-cf7db.php#L340plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 1, 2026, 9:17 AM - https://plugins.trac.wordpress.org/browser/cf7-google-sheets-connector/tags/5.1.7/includes/pages/class-gs-cf7db-formEntryList.php#L64plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 1, 2026, 9:17 AM - https://plugins.trac.wordpress.org/browser/cf7-google-sheets-connector/tags/5.1.7/includes/pages/class-gs-cf7db-formEntryList.php#L34plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 1, 2026, 9:17 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-19425CVSS 9.3 · Critical
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, m…
- CVE-2026-66770CVSS 6.3 · Medium
Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Language) string into the underlying…
- CVE-2026-72908CVSS 6.5 · Medium
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts/doctype/tax_rule/tax_rule.py…
- CVE-2025-13294CVSS 9.3 · Critical
An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacker-controlled parameters direct…
- CVE-2026-72899CVSS 10.0 · Critical
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter.
- CVE-2026-72898CVSS 10.0 · Critical
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase inst…