Impact
The vulnerability is an open redirect that occurs when the plugin processes URLs entered by users or interstitial forms, allowing an attacker to redirect visitors to a malicious site for phishing or social engineering attacks. The weakness is a classic CWE‑601 scenario where user‑controlled input is passed to the browser without proper validation.
Affected Systems
The flaw exists in the CRM Perks Connector for Gravity Forms and Google Sheets plugin for WordPress. All installations running version 1.2.4 or earlier are affected; the issue is reported to impact every release from the initial version up to and including 1.2.4.
Risk and Exploitability
With a CVSS base score of 4.7 the defect presents moderate impact, yet the EPSS score of less than 1 % indicates a low probability of exploitation at this time. Because the plugin opens redirects through user‑supplied URLs, an attacker could lure site visitors to fraudulent sites. The flaw is not listed in CISA’s KEV, but the potential phishing risk warrants remedial action.
OpenCVE Enrichment
EUVD