CVE-2025-47454: WordPress WP Gravity Forms Dynamics CRM plugin <= 1.1.4 - Open Redirection Vulnerability
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Dynamics CRM allows Phishing. This issue affects WP Gravity Forms Dynamics CRM: from n/a through 1.1.4.
Other sources
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Dynamics CRM gf-dynamics-crm allows Phishing.This issue affects WP Gravity Forms Dynamics CRM: from n/a through <= 1.1.4.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47454?
CVE-2025-47454 has a high severity level due to its potential to facilitate phishing attacks.
How do I fix CVE-2025-47454?
To fix CVE-2025-47454, update the WP Gravity Forms Dynamics CRM plugin to version 1.1.5 or later.
What versions are affected by CVE-2025-47454?
CVE-2025-47454 affects all versions of WP Gravity Forms Dynamics CRM up to and including 1.1.4.
What is an open redirect vulnerability in the context of CVE-2025-47454?
An open redirect vulnerability allows an attacker to redirect users to untrusted sites, potentially leading to phishing.
Can CVE-2025-47454 be exploited by an attacker?
Yes, an attacker can exploit CVE-2025-47454 to lead users to malicious sites through crafted links.