Description
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Object Injection.This issue affects WP Gravity Forms Keap/Infusionsoft: from n/a through <= 1.2.3.
Published: 2025-11-06
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to inject arbitrary PHP objects by deserializing data from external sources. The flaw is rooted in the deserialization handling within the Gravity Forms Keap/Infusionsoft plugin, which processes user-supplied input without adequate validation. Exploitation of this weakness can provide the attacker with the ability to execute arbitrary code on the target WordPress installation, jeopardizing system integrity and data confidentiality.

Affected Systems

The issue affects the Gravity Forms Keap/Infusionsoft plugin provided by CRM Perks, version 1.2.3 and all earlier releases. The plugin integrates with WordPress installations that use Gravity Forms to collect and manage form data. Any site that has this plugin installed and is running a vulnerable version is potentially affected.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, while the EPSS score of less than 1% shows a low yet non‑zero probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation yet. The likely attack vector is remote, through crafted requests to the plugin’s deserialization endpoint. An attacker with network access to the WordPress site could supply malicious payloads, triggering the deserialization and enabling code execution.

Generated by OpenCVE AI on April 29, 2026 at 13:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Gravity Forms Keap/Infusionsoft plugin to a version greater than 1.2.3
  • If an upgrade is not immediately possible, disable or remove the plugin until a fixed version is applied
  • Consider restricting access to the Gravity Forms endpoints by using web‑application firewall rules to block untrusted input before it reaches the plugin

Generated by OpenCVE AI on April 29, 2026 at 13:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 17 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Fri, 07 Nov 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Crm Perks
Crm Perks wp Gravity Forms Keap/infusionsoft
Wordpress
Wordpress wordpress
Vendors & Products Crm Perks
Crm Perks wp Gravity Forms Keap/infusionsoft
Wordpress
Wordpress wordpress

Thu, 06 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Object Injection.This issue affects WP Gravity Forms Keap/Infusionsoft: from n/a through <= 1.2.3.
Title WordPress WP Gravity Forms Keap/Infusionsoft Plugin <= 1.2.3 - Deserialization of untrusted data Vulnerability
Weaknesses CWE-502
References

Subscriptions

Crm Perks Wp Gravity Forms Keap/infusionsoft
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:14:24.565Z

Reserved: 2025-09-03T09:03:12.361Z

Link: CVE-2025-58636

cve-icon Vulnrichment

Updated: 2025-11-17T16:22:36.072Z

cve-icon NVD

Status : Deferred

Published: 2025-11-06T16:15:59.860

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-58636

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T14:00:12Z

Weaknesses