CVE-2025-60209: WordPress Connector for Gravity Forms and Google Sheets plugin <= 1.2.6 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Object Injection.This issue affects Connector for Gravity Forms and Google Sheets: from n/a through <= 1.2.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60209?
CVE-2025-60209 is classified as a high severity vulnerability due to its potential for object injection from deserialization of untrusted data.
How do I fix CVE-2025-60209?
To fix CVE-2025-60209, update the CRM Perks Connector for Gravity Forms and Google Sheets to version 1.2.7 or later.
What versions are affected by CVE-2025-60209?
CVE-2025-60209 affects all versions of CRM Perks Connector for Gravity Forms and Google Sheets from n/a through 1.2.6.
What type of vulnerability is CVE-2025-60209?
CVE-2025-60209 is a deserialization vulnerability that allows for object injection.
Which products are impacted by CVE-2025-60209?
CVE-2025-60209 impacts the CRM Perks Connector for Gravity Forms and Google Sheets and the WordPress version of the same connector.