Object Injection Vulnerability in PDF for Gravity Forms by WordPress
CVE-2025-60080
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 December 2025
What is CVE-2025-60080?
A deserialization vulnerability exists within the PDF for Gravity Forms + Drag And Drop Template Builder plugin, allowing for potential object injection. This flaw impacts versions up to 6.3.0, creating risks for users who have not updated their installations. Attackers may exploit this vulnerability to manipulate objects in a way that could compromise site security. It is crucial for WordPress users leveraging this plugin to take immediate action in updating to safer versions and fortifying their defenses against such attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PDF for Gravity Forms + Drag And Drop Template Builder <= n/a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved