Deserialization of Untrusted Data in CRM Perks Connector for Gravity Forms by a leading WordPress vendor
CVE-2025-60209

9.8CRITICAL

What is CVE-2025-60209?

The CRM Perks Connector for Gravity Forms and Google Sheets contains a vulnerability that allows for the deserialization of untrusted data, leading to potential object injection attacks. This issue impacts versions of the Connector for Gravity Forms and Google Sheets up to and including 1.2.6. Exploiting this vulnerability could allow an attacker to introduce malicious objects into the application's data processing workflows, possibly compromising the integrity and security of the system.

Affected Version(s)

Connector for Gravity Forms and Google Sheets <= n/a

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock (Patchstack Alliance)
.
CVE-2025-60209 : Deserialization of Untrusted Data in CRM Perks Connector for Gravity Forms by a leading WordPress vendor