Impact
A flaw in the WP Gravity Forms HubSpot plugin constitutes a CWE-601 open redirect vulnerability, allowing a malicious actor to generate URLs that redirect users to any external domain. This redirect can be used to lure users into phishing sites, compromising confidentiality and potentially leading to credential theft.
Affected Systems
WordPress sites that have the CRM Perks WP Gravity Forms HubSpot plugin at any version through 1.2.5 are impacted, regardless of exact build numbers. The issue does not affect newer releases above 1.2.5 if available.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate risk. EPSS indicates less than 1% exploitation probability, and the vulnerability is not part of the CISA KEV catalog. Attackers can exploit the weakness by embedding crafted links in emails or web pages; however, the need for a user to click the link keeps the exploitation likelihood low.
OpenCVE Enrichment