CVE-2025-60151: WordPress WP Gravity Forms HubSpot Plugin <= 1.2.5 - Open Redirection Vulnerability
Published Oct 22, 2025
·Updated
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Phishing.This issue affects WP Gravity Forms HubSpot: from n/a through <= 1.2.5.
Affected Software
1 affected component
CRM Perks WP Gravity Forms HubSpot<=1.2.5
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-60151?
CVE-2025-60151 is classified as a URL Redirection to Untrusted Site vulnerability which can potentially allow phishing attacks.
2
How do I fix CVE-2025-60151?
To fix CVE-2025-60151, update the WP Gravity Forms HubSpot plugin to a version later than 1.2.5.
3
Which versions of WP Gravity Forms HubSpot are affected by CVE-2025-60151?
CVE-2025-60151 affects WP Gravity Forms HubSpot versions from n/a through 1.2.5 inclusive.
4
What impact does CVE-2025-60151 have on users?
CVE-2025-60151 can lead to users being redirected to untrusted sites, increasing the risk of phishing.
5
Who is responsible for addressing CVE-2025-60151?
The vendor, CRM Perks, is responsible for providing updates and fixes for CVE-2025-60151.