CVE-2025-30954: WordPress WP Gravity Forms Constant Contact Plugin <= 1.1.0 - Open Redirection Vulnerability
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin allows Phishing. This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through 1.1.0.
Other sources
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Constant Contact Plugin gf-constant-contact allows Phishing.This issue affects WP Gravity Forms Constant Contact Plugin: from n/a through <= 1.1.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30954?
CVE-2025-30954 is classified as a medium severity vulnerability due to its potential for enabling phishing attacks.
How do I fix CVE-2025-30954?
To fix CVE-2025-30954, update the WP Gravity Forms Constant Contact Plugin to the latest version beyond 1.1.0.
What type of vulnerability is CVE-2025-30954?
CVE-2025-30954 is an Open Redirect vulnerability that allows redirection to untrusted websites.
Who is affected by CVE-2025-30954?
CVE-2025-30954 affects users of the WP Gravity Forms Constant Contact Plugin version 1.1.0 and earlier.
What can attackers do with CVE-2025-30954?
Attackers can exploit CVE-2025-30954 to carry out phishing scams by redirecting users to malicious sites.