Description
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.5.1.
Published: 2025-12-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WordPress WP Gravity Forms Salesforce plugin contains a deserialization bug that allows an attacker to inject PHP objects via untrusted data. This PHP Object Injection can lead to arbitrary code execution on the server, granting the attacker the ability to compromise the web application. The flaw stems from the plugin's handling of form submissions that are deserialized without proper validation, and the vulnerability is identified as CWE‑502.

Affected Systems

The affected software is the CRM Perks WP Gravity Forms Salesforce WordPress plugin for all installations up to and including version 1.5.1. Any WordPress site running the plugin in those versions without an upgrade is potentially exposed.

Risk and Exploitability

The vulnerability can be leveraged by an attacker to inject PHP objects via untrusted data processed by the plugin. Based on the description, an attacker may be able to exploit this flaw by submitting specially crafted data to the form handling logic, although the exact exploitation vector is not detailed in the advisory. The EPSS score of less than 1 % indicates a low probability of current exploitation, and the issue is not listed in CISA KEV. The high CVSS of 9.8 signals a critical severity; therefore, administrators should consider the risk high and take remedial action.

Generated by OpenCVE AI on April 29, 2026 at 18:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the CRM Perks WP Gravity Forms Salesforce plugin to a version newer than 1.5.1 to address the deserialization bug.
  • Implement strict input validation or sanitization for any data that will be deserialized by the plugin, rejecting or escaping potentially malicious payloads to mitigate Object Injection as per CWE‑502.
  • If an upgrade cannot be performed immediately, disable or uninstall the plugin to eliminate the attack surface.

Generated by OpenCVE AI on April 29, 2026 at 18:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 31 Dec 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Crmperks
Crmperks wp Gravity Forms Salesforce
CPEs cpe:2.3:a:crmperks:wp_gravity_forms_salesforce:*:*:*:*:*:wordpress:*:*
Vendors & Products Crmperks
Crmperks wp Gravity Forms Salesforce

Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Crm Perks
Crm Perks wp Gravity Forms Hubspot
Wordpress
Wordpress wordpress
Vendors & Products Crm Perks
Crm Perks wp Gravity Forms Hubspot
Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.5.1.
Title WordPress WP Gravity Forms Salesforce plugin <= 1.5.1 - PHP Object Injection vulnerability
Weaknesses CWE-502
References

Subscriptions

Crm Perks Wp Gravity Forms Hubspot
Crmperks Wp Gravity Forms Salesforce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:39:24.245Z

Reserved: 2025-09-25T15:28:27.829Z

Link: CVE-2025-60180

cve-icon Vulnrichment

Updated: 2025-12-18T18:58:51.809Z

cve-icon NVD

Status : Modified

Published: 2025-12-18T08:16:09.737

Modified: 2026-01-20T15:17:29.000

Link: CVE-2025-60180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:00:06Z

Weaknesses