CVE-2025-60091: WordPress WP Gravity Forms Zoho CRM and Bigin plugin <= 1.2.9 - Deserialization of untrusted data vulnerability
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Object Injection.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60091?
CVE-2025-60091 is classified as a high severity vulnerability due to its potential for remote code execution through object injection.
How do I fix CVE-2025-60091?
To fix CVE-2025-60091, update the WP Gravity Forms Zoho CRM and Bigin plugin to the latest version beyond 1.2.9.
Which versions are affected by CVE-2025-60091?
CVE-2025-60091 affects all versions of the WP Gravity Forms Zoho CRM and Bigin plugin up to and including 1.2.9.
What type of vulnerability is CVE-2025-60091?
CVE-2025-60091 is a deserialization of untrusted data vulnerability that allows for object injection.
Who is impacted by CVE-2025-60091?
Users of the WP Gravity Forms Zoho CRM and Bigin plugin on WordPress are impacted by CVE-2025-60091.