PT-2025-52150 · WordPress · Crm Perks Wp Gravity Forms Salesforce

·

CVE-2025-60180

·

Published

2025-12-18

·

Updated

2025-12-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CRM Perks WP Gravity Forms Salesforce versions through 1.5.1
Description A flaw exists in CRM Perks WP Gravity Forms Salesforce that allows for object injection due to deserialization of untrusted data. This issue could potentially allow for malicious code execution.
Recommendations Update CRM Perks WP Gravity Forms Salesforce to a version later than 1.5.1.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60180

Affected Products

Crm Perks Wp Gravity Forms Salesforce