Deserialization of Untrusted Data in CRM Perks Connector for Gravity Forms by a leading WordPress vendor
CVE-2025-60209
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 October 2025
What is CVE-2025-60209?
The CRM Perks Connector for Gravity Forms and Google Sheets contains a vulnerability that allows for the deserialization of untrusted data, leading to potential object injection attacks. This issue impacts versions of the Connector for Gravity Forms and Google Sheets up to and including 1.2.6. Exploiting this vulnerability could allow an attacker to introduce malicious objects into the application's data processing workflows, possibly compromising the integrity and security of the system.
Affected Version(s)
Connector for Gravity Forms and Google Sheets <= n/a