Impact
A vulnerability in the WP Gravity Forms FreshDesk Plugin allows an attacker to manipulate URL redirection parameters so that users can be redirected to an untrusted site. This opens the door for phishing attacks, credential harvesting or malware delivery. The weakness is classified as CWE‑601, an insecure redirect that bypasses trust boundaries.
Affected Systems
The plugin is distributed by CRM Perks as the WP Gravity Forms FreshDesk Plugin. All released versions up to and including 1.3.5 are vulnerable. Any WordPress installation using a version in this range should be considered affected.
Risk and Exploitability
The CVSS score is 4.7, indicating a medium severity vulnerability. The EPSS score is less than 1%, suggesting that exploitation is unlikely at present. It is not listed in the CISA KEV catalog. Attack likely occurs when a user follows a crafted link that the plugin redirects to an external domain. An attacker could therefore trick legitimate users into visiting a malicious site to steal credentials or deliver malware.
OpenCVE Enrichment