CVE-2025-60091: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60091 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the CRM Perks WP Gravity Forms Zoho CRM and Bigin WordPress plugin (gf-zoho) that enables PHP Object Injection. It affects all plugin versions from the initial release through and including 1.2.9, with version 1.3.0 introducing the fix. The vulnerability was published on December 18, 2025, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, ENISA EUVD).

Technical details

The root cause is improper deserialization of user-supplied data (CWE-502 / CAPEC-586: Object Injection) within the gf-zoho plugin. When the plugin processes attacker-controlled input, it passes it to PHP's unserialize() (or an equivalent mechanism) without adequate validation, allowing an attacker to instantiate arbitrary PHP objects. If a suitable "gadget chain" exists in the WordPress environment (e.g., from other installed plugins or themes), this object injection can be escalated to remote code execution, arbitrary file write/delete, or other critical impacts. No authentication or user interaction is required, and the attack is conducted entirely over the network (Feedly).

Impact

Successful exploitation can result in complete compromise of the affected WordPress installation across all three security dimensions: full confidentiality loss (access to sensitive data, credentials, and database contents), full integrity loss (arbitrary code execution, file manipulation, or content defacement), and full availability loss (site takedown or resource exhaustion). Because no authentication is required, any internet-facing WordPress site running the vulnerable plugin is at risk. Depending on available gadget chains in the environment, attackers may achieve remote code execution and use the compromised server as a pivot point for lateral movement within the hosting infrastructure (Feedly).

Exploitability

As of the disclosure date (December 18, 2025), there is no public proof-of-concept and no confirmed in-the-wild exploitation reported. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.024%, indicating a currently low probability of near-term exploitation. However, the unauthenticated, network-accessible attack vector and critical CVSS score make it a high-priority patching target, particularly for sites with complex plugin ecosystems that may provide usable gadget chains (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the gf-zoho plugin (WP Gravity Forms Zoho CRM and Bigin) version ≤ 1.2.9 using passive techniques such as searching for the plugin's readme file at /wp-content/plugins/gf-zoho/readme.txt or using tools like WPScan.
  2. Gadget chain enumeration: Enumerate other installed plugins and themes on the target to identify PHP classes that can be abused as deserialization gadget chains (e.g., classes with __wakeup, __destruct, or __toString magic methods that perform dangerous operations).
  3. Craft malicious payload: Using a tool such as PHPGGC, generate a serialized PHP object payload targeting an available gadget chain that achieves the desired impact (e.g., remote code execution, arbitrary file write).
  4. Deliver payload: Submit the crafted serialized payload to the vulnerable plugin endpoint that performs unserialization, without requiring any authentication credentials.
  5. Achieve objective: If a suitable gadget chain is present, the deserialized object triggers the chain's magic methods, resulting in code execution, file manipulation, or other attacker-defined outcomes on the WordPress server.

Indicators of compromise

  • Network: Unexpected or malformed POST requests to plugin-specific endpoints under /wp-content/plugins/gf-zoho/ or WordPress AJAX handlers (/wp-admin/admin-ajax.php) containing serialized PHP data (strings beginning with O:, a:, s:, etc.).
  • Logs: Web server access logs showing requests to gf-zoho plugin endpoints with unusually large or encoded body content; PHP error logs referencing unserialize() warnings or unexpected class instantiation.
  • File System: Newly created or modified PHP files in the WordPress webroot or plugin directories (potential web shells); unexpected changes to wp-config.php or .htaccess.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, curl, wget, python) that are not part of normal WordPress operation.
  • Database: New or modified WordPress administrator accounts; unexpected changes to wp_options table entries (e.g., siteurl, admin_email).

Mitigation and workarounds

The primary remediation is to update the WP Gravity Forms Zoho CRM and Bigin plugin to version 1.3.0 or later, which resolves the deserialization issue. If an immediate update is not possible, temporarily deactivate and remove the plugin to eliminate the attack surface. Additionally, implement network-level controls to restrict access to the WordPress admin interface, deploy a Web Application Firewall (WAF) rule to block requests containing serialized PHP payloads, and conduct a security audit of all installed plugins and themes to identify potential gadget chains. Monitor server logs for anomalous activity as described in the IOCs section (Feedly).

Community reactions

The vulnerability was discovered and reported by Patchstack, which assigned the CVE and published the advisory on December 18, 2025. No notable independent researcher commentary, vendor statements beyond the patch release, or significant media coverage has been identified at this time.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management