CVE-2025-47456: WordPress WP Gravity Forms Zendesk plugin <= 1.1.2 - Open Redirection Vulnerability
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zendesk allows Phishing. This issue affects WP Gravity Forms Zendesk: from n/a through 1.1.2.
Other sources
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zendesk gf-zendesk allows Phishing.This issue affects WP Gravity Forms Zendesk: from n/a through <= 1.1.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47456?
CVE-2025-47456 is a moderate severity vulnerability that allows URL redirection to untrusted sites.
How do I fix CVE-2025-47456?
To resolve CVE-2025-47456, update your WP Gravity Forms Zendesk plugin to version 1.1.3 or later.
What impact does CVE-2025-47456 have on my website?
CVE-2025-47456 can lead to phishing attacks as it enables attackers to redirect users to malicious sites.
Which versions are affected by CVE-2025-47456?
CVE-2025-47456 affects all versions of WP Gravity Forms Zendesk up to and including version 1.1.2.
Is CVE-2025-47456 specific to any platforms?
CVE-2025-47456 specifically affects the WP Gravity Forms Zendesk plugin within WordPress.