CVE-2025-30953: WordPress WP Gravity Forms Salesforce plugin <= 1.4.7 - Open Redirection Vulnerability
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Salesforce allows Phishing. This issue affects WP Gravity Forms Salesforce: from n/a through 1.4.7.
Other sources
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Phishing.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.4.7.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30953?
CVE-2025-30953 is considered a medium severity vulnerability due to its potential for facilitating phishing attacks.
How do I fix CVE-2025-30953?
To fix CVE-2025-30953, upgrade to WP Gravity Forms Salesforce version 1.4.8 or later.
Who is affected by CVE-2025-30953?
CVE-2025-30953 affects users of WP Gravity Forms Salesforce versions up to and including 1.4.7.
What type of vulnerability is CVE-2025-30953?
CVE-2025-30953 is classified as an Open Redirect vulnerability, which may lead to untrusted site redirection.
What can attackers do with CVE-2025-30953?
Attackers can exploit CVE-2025-30953 to redirect users to untrusted sites, potentially leading to phishing attacks.