
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60080 is a Deserialization of Untrusted Data (PHP Object Injection) vulnerability in the "PDF for Gravity Forms + Drag And Drop Template Builder" WordPress plugin developed by add-ons.org. The vulnerability affects all versions of the plugin up to and including 6.5.0 (per NVD) or 6.3.0 (per ENISA/Patchstack). It was published on December 18, 2025, and assigned by Patchstack. The CVSS v3.1 base score is 7.5 (High) (Feedly).
The vulnerability is classified under CWE-502 (Deserialization of Untrusted Data) and maps to CAPEC-586 (Object Injection). An authenticated attacker with low privileges can send a crafted network request containing a malicious serialized PHP object, which the plugin deserializes without adequate validation or sanitization. Successful exploitation requires high attack complexity and no user interaction, suggesting that specific conditions or gadget chains within the WordPress environment must be met to achieve meaningful impact (Feedly).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected WordPress installation. Depending on available PHP gadget chains in the environment, an attacker could achieve arbitrary code execution, read or modify sensitive data, delete files, or cause a denial of service. The scope is unchanged, meaning the impact is contained to the vulnerable component and its host environment, but lateral movement within the server is possible if code execution is achieved (Feedly).
The EPSS score for CVE-2025-60080 is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the wild. No public proof-of-concept exploit code, active in-the-wild exploitation, or threat actor attribution has been reported at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low-privilege authentication and high attack complexity, which somewhat limits opportunistic exploitation (Feedly).
__wakeup, __destruct, etc.) in the gadget chain, achieving the attacker's objective (e.g., remote code execution, file deletion, or data exfiltration) (Feedly).O:<length>:"<classname>" patterns in request bodies or parameters).bash, curl, wget) following plugin endpoint requests.Users should update the "PDF for Gravity Forms + Drag And Drop Template Builder" plugin to a version beyond 6.5.0 (the latest patched release) as soon as one becomes available from add-ons.org or the WordPress plugin repository. In the interim, site administrators should consider deactivating or removing the plugin if it is not critical to operations. Restricting access to WordPress contributor/subscriber registration and applying a web application firewall (WAF) rule to block serialized PHP object patterns in HTTP requests can serve as additional mitigations (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."