Impact
The WP Gravity Forms Zendesk plugin contains an open redirect flaw that allows attackers to craft URLs which redirect visitors to malicious sites, facilitating phishing campaigns. This flaw stems from inadequate validation of redirect targets, identified as CWE‑601. The vulnerability lacks direct impact on data confidentiality or integrity but can undermine user trust and facilitate credential theft.
Affected Systems
The issue affects the WP Gravity Forms Zendesk plugin from its first release through version 1.1.2, released by CRM Perks. Any WordPress installation using this plugin within that version range is relevant.
Risk and Exploitability
With a CVSS score of 4.7 the risk is moderate, yet the EPSS score of less than 1% indicates a low probability of exploitation at present, and the vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is a user clicking a manipulated link constructed with the plugin’s redirect parameter, which is inferred from the description of the open redirect flaw.
OpenCVE Enrichment
EUVD