CVE-2025-60174
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60174 is a Deserialization of Untrusted Data vulnerability (Object Injection) in the WP Gravity Forms Constant Contact Plugin by CRM Perks for WordPress. It affects all versions up to and including 1.1.2, and was reported by researcher Phat RiO on July 9, 2025, with public disclosure on August 8, 2025. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), exploitable by unauthenticated remote attackers with no user interaction required (Patchstack).

Technical details

The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The plugin fails to safely handle serialized PHP data supplied by unauthenticated users, allowing an attacker to inject a crafted serialized object that, when deserialized server-side, can trigger arbitrary PHP class instantiation and method invocation (a PHP Object Injection attack). Exploitation requires no authentication, no special privileges, and no user interaction, making it trivially exploitable over the network. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation can result in complete compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. Depending on available PHP gadget chains in the WordPress environment, an attacker could achieve remote code execution, gain administrative access, exfiltrate sensitive data, or cause a denial of service. The unauthenticated, network-accessible nature of the flaw means any internet-facing WordPress site running the vulnerable plugin is at risk of mass exploitation (Patchstack).

Exploitability

No public proof-of-concept exploit or evidence of in-the-wild exploitation has been observed as of the time of disclosure. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class and severity are frequently used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Gravity Forms Constant Contact Plugin (plugin slug: gf-constant-contact) version 1.1.2 or earlier using tools like WPScan, Shodan, or by checking publicly accessible readme.txt files at /wp-content/plugins/gf-constant-contact/readme.txt.
  2. Identify vulnerable endpoint: Locate the plugin's input handling endpoint(s) that accept and process serialized PHP data without authentication.
  3. Craft malicious payload: Construct a serialized PHP object payload targeting a known gadget chain present in the WordPress/plugin environment (e.g., using tools like PHPGGC to generate gadget chains for common WordPress libraries).
  4. Submit payload: Send the crafted serialized object to the vulnerable endpoint via an unauthenticated HTTP request.
  5. Trigger deserialization: The server deserializes the malicious object, invoking magic methods (__wakeup, __destruct, etc.) that execute attacker-controlled logic.
  6. Achieve objective: Depending on the gadget chain, achieve remote code execution, write a web shell, escalate to admin, or exfiltrate data (Patchstack).

Indicators of compromise

  • Network: Unusual or repeated unauthenticated POST requests to plugin-related endpoints on WordPress sites; outbound connections from the web server to unknown external IPs following such requests.
  • File System: Unexpected PHP files (web shells) created in /wp-content/plugins/gf-constant-contact/ or other writable WordPress directories; modification timestamps on plugin files inconsistent with legitimate updates.
  • Logs: WordPress or web server access logs showing POST requests with large, encoded, or binary-looking body content to plugin endpoints from unfamiliar IP addresses; PHP error logs referencing unexpected class instantiation or magic method calls.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, curl, wget, python) that are not part of normal WordPress operation.

Mitigation and workarounds

The vendor has released version 1.1.3 of the WP Gravity Forms Constant Contact Plugin, which patches this vulnerability. Site administrators should update to version 1.1.3 or later immediately via the WordPress plugin dashboard. As interim mitigations, administrators can restrict access to the WordPress site using a web application firewall (WAF) — Patchstack has issued a virtual patch/mitigation rule for its users. Additionally, applying the principle of least privilege, monitoring for suspicious activity, and implementing input validation at the application layer are recommended defensive measures (Patchstack).

Community reactions

The vulnerability was discovered and disclosed by security researcher Phat RiO through Patchstack's coordinated disclosure process. Patchstack has classified it as high priority and noted that vulnerabilities of this type are commonly leveraged in mass WordPress exploitation campaigns. No significant broader media coverage or notable social media discussion has been identified beyond the Patchstack advisory (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18039NONEN/A
  • essential-addons-for-elementor-lite
NoYesAug 14, 2026
CVE-2026-16810NONEN/A
  • bit-form
NoYesAug 14, 2026
CVE-2026-16739NONEN/A
  • epeken-all-kurir
NoNoAug 14, 2026
CVE-2026-15205NONEN/A
  • paymob-for-woocommerce
NoYesAug 14, 2026
CVE-2026-14290NONEN/A
  • embed-google-photos-album-easily
NoNoAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management