CVE-2025-60089: WordPress WP Gravity Forms FreshDesk plugin plugin <= 1.3.5 - Deserialization of untrusted data vulnerability
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60089?
CVE-2025-60089 is classified as a critical vulnerability due to its potential for object injection and exploitation.
How do I fix CVE-2025-60089?
To fix CVE-2025-60089, you should update the WP Gravity Forms FreshDesk Plugin to a version higher than 1.3.5.
What types of systems are affected by CVE-2025-60089?
CVE-2025-60089 affects the WP Gravity Forms FreshDesk Plugin version 1.3.5 and earlier.
What can an attacker do with CVE-2025-60089?
An attacker can exploit CVE-2025-60089 to perform remote code execution through object injection, potentially leading to a complete system compromise.
Is CVE-2025-60089 easy to exploit?
Yes, CVE-2025-60089 is considered relatively easy to exploit, making it important to address quickly.