CVE-2025-60090: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60090 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the CRM Perks WP Gravity Forms Insightly WordPress plugin (gf-insightly) that enables PHP Object Injection. It affects all plugin versions from the initial release through 1.1.6 (inclusive), and was published on December 18, 2025 by Patchstack. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), reflecting network-accessible exploitation with no authentication or user interaction required (Feedly, EUVD).

Technical details

The root cause is improper deserialization of user-supplied data (CWE-502 / CAPEC-586: Object Injection) within the WP Gravity Forms Insightly plugin. When the plugin processes attacker-controlled input, it passes it to PHP's unserialize() (or an equivalent mechanism) without adequate validation, allowing an attacker to inject a crafted serialized PHP object. If a suitable "gadget chain" exists in the WordPress environment (e.g., from other installed plugins or themes), the deserialized object can trigger arbitrary code execution, file manipulation, or other malicious actions. No authentication or user interaction is required, and the attack is conducted entirely over the network (Feedly).

Impact

Successful exploitation can result in full compromise of the affected WordPress site, with high impact on confidentiality, integrity, and availability. An unauthenticated remote attacker could execute arbitrary PHP code, read or exfiltrate sensitive data (including credentials and database contents), modify or delete site content, and potentially pivot to the underlying server or other hosted applications. The absence of any authentication requirement makes this vulnerability particularly dangerous for any internet-facing WordPress installation running the affected plugin (Feedly).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024%, indicating a currently low probability of near-term exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the critical CVSS score, lack of authentication requirement, and the prevalence of WordPress plugin gadget chains make it an attractive target if a PoC is developed (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the gf-insightly plugin in version ≤ 1.1.6 using tools such as WPScan, Shodan, or by inspecting publicly accessible plugin metadata (e.g., readme.txt at /wp-content/plugins/gf-insightly/readme.txt).
  2. Identify the vulnerable deserialization endpoint: Analyze the plugin's source code (available from the WordPress plugin repository) to locate the parameter or request handler that passes user input to unserialize() without sanitization.
  3. Identify a gadget chain: Survey other installed plugins and themes on the target for known PHP object injection gadget chains (e.g., using tools like PHPGGC) that can be triggered upon deserialization.
  4. Craft a malicious serialized payload: Use PHPGGC or a custom script to generate a serialized PHP object payload targeting the identified gadget chain, designed to execute a desired action (e.g., write a web shell, execute OS commands).
  5. Deliver the payload: Submit the crafted serialized payload to the vulnerable endpoint via an unauthenticated HTTP request (GET or POST, depending on the plugin's implementation).
  6. Achieve code execution: The server deserializes the payload, triggers the gadget chain, and executes the attacker's code — enabling web shell upload, data exfiltration, or further lateral movement within the hosting environment.

Indicators of compromise

  • Network: Unusual HTTP requests (GET or POST) to plugin-specific endpoints under /wp-content/plugins/gf-insightly/ containing long, base64-encoded, or binary-looking parameter values consistent with serialized PHP objects (O:, a:, s: prefixes).
  • Logs: WordPress or web server access logs showing repeated or anomalous requests to the plugin's PHP files from unexpected IP addresses, particularly with large or malformed request bodies.
  • File System: Newly created or modified PHP files in the WordPress installation directory (especially in wp-content/uploads/ or plugin directories) that were not part of a legitimate update; presence of web shells (e.g., files containing eval(, base64_decode(, system(, passthru().
  • Process: Unexpected child processes spawned by the web server process (e.g., apache2, nginx, php-fpm) such as bash, sh, curl, wget, or python.
  • Database: Unexpected changes to WordPress options, user accounts (new admin users), or scheduled events (wp_cron) that could indicate post-exploitation persistence.

Mitigation and workarounds

The primary remediation is to update the WP Gravity Forms Insightly plugin to version 1.1.7 or later, which addresses this vulnerability. Site administrators who cannot immediately update should consider temporarily deactivating the plugin to eliminate the attack surface. Additional hardening measures include implementing a web application firewall (WAF) rule to block requests containing serialized PHP object patterns, applying the principle of least privilege to the WordPress database user, and auditing other installed plugins for known gadget chains. Monitoring server logs for anomalous deserialization-related activity is also recommended (Feedly).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management