
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60091 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the CRM Perks WP Gravity Forms Zoho CRM and Bigin WordPress plugin (gf-zoho) that enables PHP Object Injection. It affects all plugin versions from the initial release through and including 1.2.9, with version 1.3.0 introducing the fix. The vulnerability was published on December 18, 2025, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, ENISA EUVD).
The root cause is improper deserialization of user-supplied data (CWE-502 / CAPEC-586: Object Injection) within the gf-zoho plugin. When the plugin processes attacker-controlled input, it passes it to PHP's unserialize() (or an equivalent mechanism) without adequate validation, allowing an attacker to instantiate arbitrary PHP objects. If a suitable "gadget chain" exists in the WordPress environment (e.g., from other installed plugins or themes), this object injection can be escalated to remote code execution, arbitrary file write/delete, or other critical impacts. No authentication or user interaction is required, and the attack is conducted entirely over the network (Feedly).
Successful exploitation can result in complete compromise of the affected WordPress installation across all three security dimensions: full confidentiality loss (access to sensitive data, credentials, and database contents), full integrity loss (arbitrary code execution, file manipulation, or content defacement), and full availability loss (site takedown or resource exhaustion). Because no authentication is required, any internet-facing WordPress site running the vulnerable plugin is at risk. Depending on available gadget chains in the environment, attackers may achieve remote code execution and use the compromised server as a pivot point for lateral movement within the hosting infrastructure (Feedly).
As of the disclosure date (December 18, 2025), there is no public proof-of-concept and no confirmed in-the-wild exploitation reported. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.024%, indicating a currently low probability of near-term exploitation. However, the unauthenticated, network-accessible attack vector and critical CVSS score make it a high-priority patching target, particularly for sites with complex plugin ecosystems that may provide usable gadget chains (Feedly).
gf-zoho plugin (WP Gravity Forms Zoho CRM and Bigin) version ≤ 1.2.9 using passive techniques such as searching for the plugin's readme file at /wp-content/plugins/gf-zoho/readme.txt or using tools like WPScan.__wakeup, __destruct, or __toString magic methods that perform dangerous operations)./wp-content/plugins/gf-zoho/ or WordPress AJAX handlers (/wp-admin/admin-ajax.php) containing serialized PHP data (strings beginning with O:, a:, s:, etc.).gf-zoho plugin endpoints with unusually large or encoded body content; PHP error logs referencing unserialize() warnings or unexpected class instantiation.wp-config.php or .htaccess.bash, curl, wget, python) that are not part of normal WordPress operation.wp_options table entries (e.g., siteurl, admin_email).The primary remediation is to update the WP Gravity Forms Zoho CRM and Bigin plugin to version 1.3.0 or later, which resolves the deserialization issue. If an immediate update is not possible, temporarily deactivate and remove the plugin to eliminate the attack surface. Additionally, implement network-level controls to restrict access to the WordPress admin interface, deploy a Web Application Firewall (WAF) rule to block requests containing serialized PHP payloads, and conduct a security audit of all installed plugins and themes to identify potential gadget chains. Monitor server logs for anomalous activity as described in the IOCs section (Feedly).
The vulnerability was discovered and reported by Patchstack, which assigned the CVE and published the advisory on December 18, 2025. No notable independent researcher commentary, vendor statements beyond the patch release, or significant media coverage has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."