
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60174 is a Deserialization of Untrusted Data vulnerability (Object Injection) in the WP Gravity Forms Constant Contact Plugin by CRM Perks for WordPress. It affects all versions up to and including 1.1.2, and was reported by researcher Phat RiO on July 9, 2025, with public disclosure on August 8, 2025. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), exploitable by unauthenticated remote attackers with no user interaction required (Patchstack).
The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The plugin fails to safely handle serialized PHP data supplied by unauthenticated users, allowing an attacker to inject a crafted serialized object that, when deserialized server-side, can trigger arbitrary PHP class instantiation and method invocation (a PHP Object Injection attack). Exploitation requires no authentication, no special privileges, and no user interaction, making it trivially exploitable over the network. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation can result in complete compromise of the affected WordPress site, with high impact to confidentiality, integrity, and availability. Depending on available PHP gadget chains in the WordPress environment, an attacker could achieve remote code execution, gain administrative access, exfiltrate sensitive data, or cause a denial of service. The unauthenticated, network-accessible nature of the flaw means any internet-facing WordPress site running the vulnerable plugin is at risk of mass exploitation (Patchstack).
No public proof-of-concept exploit or evidence of in-the-wild exploitation has been observed as of the time of disclosure. The EPSS score is approximately 0.024% (0.000240), indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class and severity are frequently used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
gf-constant-contact) version 1.1.2 or earlier using tools like WPScan, Shodan, or by checking publicly accessible readme.txt files at /wp-content/plugins/gf-constant-contact/readme.txt.__wakeup, __destruct, etc.) that execute attacker-controlled logic./wp-content/plugins/gf-constant-contact/ or other writable WordPress directories; modification timestamps on plugin files inconsistent with legitimate updates.bash, curl, wget, python) that are not part of normal WordPress operation.The vendor has released version 1.1.3 of the WP Gravity Forms Constant Contact Plugin, which patches this vulnerability. Site administrators should update to version 1.1.3 or later immediately via the WordPress plugin dashboard. As interim mitigations, administrators can restrict access to the WordPress site using a web application firewall (WAF) — Patchstack has issued a virtual patch/mitigation rule for its users. Additionally, applying the principle of least privilege, monitoring for suspicious activity, and implementing input validation at the application layer are recommended defensive measures (Patchstack).
The vulnerability was discovered and disclosed by security researcher Phat RiO through Patchstack's coordinated disclosure process. Patchstack has classified it as high priority and noted that vulnerabilities of this type are commonly leveraged in mass WordPress exploitation campaigns. No significant broader media coverage or notable social media discussion has been identified beyond the Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."