CVE-2025-60180: WordPress WP Gravity Forms Salesforce plugin <= 1.5.1 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Salesforce gf-salesforce-crmperks allows Object Injection.This issue affects WP Gravity Forms Salesforce: from n/a through <= 1.5.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60180?
CVE-2025-60180 is categorized as a high severity vulnerability due to the potential for object injection through deserialization of untrusted data.
How do I fix CVE-2025-60180?
To fix CVE-2025-60180, you should update the WP Gravity Forms Salesforce plugin to a version newer than 1.5.1.
What systems are affected by CVE-2025-60180?
CVE-2025-60180 affects the WP Gravity Forms Salesforce plugin version 1.5.1 and earlier.
What is deserialization of untrusted data in the context of CVE-2025-60180?
In the context of CVE-2025-60180, deserialization of untrusted data refers to the process of converting data from a byte stream back into an object without proper validation, which can lead to object injection vulnerabilities.
What should I do if I cannot update the plugin related to CVE-2025-60180?
If you cannot update the plugin related to CVE-2025-60180, you should consider disabling the plugin until a patch can be applied.