Impact
The vulnerability is an open redirection flaw that lets attackers force users to be redirected to an untrusted site, facilitating phishing and other social‑engineering attacks. The weakness arises from improper validation of redirect URLs within the Gravity Forms Dynamics CRM plugin, allowing an attacker to craft a URL that, when visited by a user, immediately sends them to a malicious domain.
Affected Systems
The flaw affects the WordPress plugin "CRM Perks WP Gravity Forms Dynamics CRM" for all released versions up to and including 1.1.4. WordPress sites that have installed or are running this plugin version are vulnerable.
Risk and Exploitability
With a CVSS score of 4.7 the vulnerability is classified as moderate severity, and its EPSS score of less than 1% indicates a low probability of exploitation. It is not currently listed in the CISA KEV catalog. Attackers would need to lure a site user to a crafted URL, a scenario that is feasible through email or malicious links. Due to its low EPSS and lack of advanced exploitation requirements, the risk remains moderate under normal operational conditions.
OpenCVE Enrichment
EUVD