
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60090 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the CRM Perks WP Gravity Forms Insightly WordPress plugin (gf-insightly) that enables PHP Object Injection. It affects all plugin versions from the initial release through 1.1.6 (inclusive), and was published on December 18, 2025 by Patchstack. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), reflecting network-accessible exploitation with no authentication or user interaction required (Feedly, EUVD).
The root cause is improper deserialization of user-supplied data (CWE-502 / CAPEC-586: Object Injection) within the WP Gravity Forms Insightly plugin. When the plugin processes attacker-controlled input, it passes it to PHP's unserialize() (or an equivalent mechanism) without adequate validation, allowing an attacker to inject a crafted serialized PHP object. If a suitable "gadget chain" exists in the WordPress environment (e.g., from other installed plugins or themes), the deserialized object can trigger arbitrary code execution, file manipulation, or other malicious actions. No authentication or user interaction is required, and the attack is conducted entirely over the network (Feedly).
Successful exploitation can result in full compromise of the affected WordPress site, with high impact on confidentiality, integrity, and availability. An unauthenticated remote attacker could execute arbitrary PHP code, read or exfiltrate sensitive data (including credentials and database contents), modify or delete site content, and potentially pivot to the underlying server or other hosted applications. The absence of any authentication requirement makes this vulnerability particularly dangerous for any internet-facing WordPress installation running the affected plugin (Feedly).
As of the disclosure date, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024%, indicating a currently low probability of near-term exploitation. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the critical CVSS score, lack of authentication requirement, and the prevalence of WordPress plugin gadget chains make it an attractive target if a PoC is developed (Feedly).
gf-insightly plugin in version ≤ 1.1.6 using tools such as WPScan, Shodan, or by inspecting publicly accessible plugin metadata (e.g., readme.txt at /wp-content/plugins/gf-insightly/readme.txt).unserialize() without sanitization./wp-content/plugins/gf-insightly/ containing long, base64-encoded, or binary-looking parameter values consistent with serialized PHP objects (O:, a:, s: prefixes).wp-content/uploads/ or plugin directories) that were not part of a legitimate update; presence of web shells (e.g., files containing eval(, base64_decode(, system(, passthru().apache2, nginx, php-fpm) such as bash, sh, curl, wget, or python.wp_cron) that could indicate post-exploitation persistence.The primary remediation is to update the WP Gravity Forms Insightly plugin to version 1.1.7 or later, which addresses this vulnerability. Site administrators who cannot immediately update should consider temporarily deactivating the plugin to eliminate the attack surface. Additional hardening measures include implementing a web application firewall (WAF) rule to block requests containing serialized PHP object patterns, applying the principle of least privilege to the WordPress database user, and auditing other installed plugins for known gadget chains. Monitoring server logs for anomalous deserialization-related activity is also recommended (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."