CVE-2025-62981: WordPress WP Gravity Forms Zoho CRM and Bigin plugin <= 1.2.8 - Open Redirection vulnerability
Published Oct 27, 2025
·Updated
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zoho allows Phishing.This issue affects WP Gravity Forms Zoho CRM and Bigin: from n/a through <= 1.2.8.
Affected Software
1 affected component
CRM Perks WP Gravity Forms Zoho CRM and Bigin<=1.2.8
Event History
Oct 27, 2025
CVE Published
via MITRE·01:34 AM
Data Sourced
via MITRE·01:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-62981?
CVE-2025-62981 is categorized as a critical vulnerability due to its potential for phishing attacks.
2
How do I fix CVE-2025-62981?
To fix CVE-2025-62981, you should update the WP Gravity Forms Zoho CRM and Bigin plugin to version 1.2.9 or later.
3
What types of attacks can CVE-2025-62981 enable?
CVE-2025-62981 can enable attacks such as phishing by allowing redirection to untrusted sites.
4
Which versions of the software are affected by CVE-2025-62981?
CVE-2025-62981 affects all versions of WP Gravity Forms Zoho CRM and Bigin up to and including 1.2.8.
5
Who is the vendor for the affected product in CVE-2025-62981?
The vendor for the affected product in CVE-2025-62981 is CRM Perks.