CVE-2025-58636: WordPress WP Gravity Forms Keap/Infusionsoft Plugin <= 1.2.3 - Deserialization of untrusted data Vulnerability
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Object Injection.This issue affects WP Gravity Forms Keap/Infusionsoft: from n/a through <= 1.2.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58636?
CVE-2025-58636 has been classified as a high severity vulnerability due to the potential for object injection attacks.
How do I fix CVE-2025-58636?
To remediate CVE-2025-58636, upgrade WP Gravity Forms Keap/Infusionsoft to a version greater than 1.2.3.
What software is affected by CVE-2025-58636?
CVE-2025-58636 affects the WP Gravity Forms Keap/Infusionsoft plugin by CRM Perks from version n/a up to and including version 1.2.3.
What types of attacks can result from CVE-2025-58636?
CVE-2025-58636 allows for deserialization of untrusted data, which can lead to remote code execution through object injection.
Is CVE-2025-58636 being actively exploited?
As of now, there are no confirmed reports of active exploitation for CVE-2025-58636.