Impact
This vulnerability results from deserialization of untrusted data in the PDF for Gravity Forms + Drag And Drop Template Builder plugin, permitting PHP object injection. An attacker who can supply crafted input may gain the ability to execute arbitrary code, compromising the integrity, confidentiality, and availability of the affected WordPress site.
Affected Systems
The issue affects the PDF for Gravity Forms + Drag And Drop Template Builder plugin from its earliest released version up to and including 6.5.0. The plugin is distributed by add‑ons.org and is commonly used by WordPress sites that require PDF generation for Gravity Forms.
Risk and Exploitability
The CVSS score of 7.5 reflects the potential for remote code execution without privilege escalation. With an EPSS score of less than 1 percent, the likelihood of exploitation is currently low, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via HTTP requests carrying custom serialized data that the plugin processes, an approach inferred from the description of untrusted data deserialization.
OpenCVE Enrichment