Object Injection Vulnerability in PDF for Gravity Forms by WordPress
CVE-2025-60080

7.5HIGH

What is CVE-2025-60080?

A deserialization vulnerability exists within the PDF for Gravity Forms + Drag And Drop Template Builder plugin, allowing for potential object injection. This flaw impacts versions up to 6.3.0, creating risks for users who have not updated their installations. Attackers may exploit this vulnerability to manipulate objects in a way that could compromise site security. It is crucial for WordPress users leveraging this plugin to take immediate action in updating to safer versions and fortifying their defenses against such attacks.

Affected Version(s)

PDF for Gravity Forms + Drag And Drop Template Builder <= n/a

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock | Patchstack Bug Bounty Program
.
CVE-2025-60080 : Object Injection Vulnerability in PDF for Gravity Forms by WordPress