
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62099 is a Missing Authorization (Broken Access Control) vulnerability in the Signature Add-On for Gravity Forms WordPress plugin by Approveme. It allows low-privileged authenticated users (Subscriber-level or higher) to exploit incorrectly configured access control security levels, enabling unauthorized modification of signature data. The vulnerability affects all plugin versions through 1.8.6, with version 1.8.7 serving as the patched release. It was reported on September 24, 2025, and publicly disclosed on December 31, 2025, by Patchstack. The CVSS v3.1 base score is 4.3 (Medium), assigned by Patchstack (Patchstack).
The vulnerability is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before executing privileged actions related to signature management. Specifically, a missing authorization, authentication, or nonce token check in one or more plugin functions allows a low-privileged subscriber-level user to perform actions that should be restricted to higher-privileged roles. The attack vector is network-based, requires low privileges, no user interaction, and low attack complexity, making it straightforward to exploit for any authenticated WordPress user (Patchstack).
Successful exploitation allows a low-privileged authenticated attacker to modify signature data within Gravity Forms submissions, compromising the integrity of signed documents or form entries. The vulnerability has no impact on confidentiality or availability (CVSS scores of None for both), and the integrity impact is rated Low. While the scope is limited to the affected plugin's functionality, tampering with signature records could undermine trust in digitally signed documents processed through the affected WordPress site (Patchstack, Red Hat CVE).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority with no impactful threat, though they note that vulnerabilities of this class are sometimes used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
wp-admin/admin-ajax.php with the relevant action parameter) targeting the unprotected function, including modified signature data in the request body.wp-admin/admin-ajax.php with plugin-specific action parameters from low-privileged user accounts; unexpected modification timestamps on Gravity Forms signature entries.wp_gf_entry_meta or related tables) associated with Gravity Forms entries, particularly from accounts with Subscriber-level roles.The vendor has released version 1.8.7 of the Signature Add-On for Gravity Forms, which patches this vulnerability. Site administrators should update the plugin to version 1.8.7 or later immediately. If an immediate update is not possible, restricting user registration or limiting Subscriber-level access to the site can reduce exposure. Patchstack users can enable auto-update for vulnerable plugins as an additional safeguard (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."