CVE-2025-60090: WordPress WP Gravity Forms Insightly plugin <= 1.1.6 - Deserialization of untrusted data vulnerability
Published Dec 18, 2025
·Updated
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a through <= 1.1.6.
Affected Software
2 affected components
wordpress/wp-gravity-forms-insightly<=1.1.6
crmperks Wp Gravity Forms Insightly Wordpress<1.1.7
Event History
Dec 18, 2025
CVE Published
via MITRE·07:22 AM
Data Sourced
via MITRE·07:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60090?
CVE-2025-60090 has been classified as a high-severity vulnerability due to its potential for object injection leading to remote code execution.
2
How can I fix CVE-2025-60090?
To fix CVE-2025-60090, update the WP Gravity Forms Insightly plugin to version 1.1.7 or later.
3
What systems are affected by CVE-2025-60090?
CVE-2025-60090 affects WP Gravity Forms Insightly versions from n/a through 1.1.6.
4
What is the type of vulnerability for CVE-2025-60090?
CVE-2025-60090 is a deserialization of untrusted data vulnerability allowing for object injection.
5
Who is responsible for addressing CVE-2025-60090?
The developers of the WP Gravity Forms Insightly plugin are responsible for addressing and patching CVE-2025-60090.