CVE-2025-67587: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67587 is an Open Redirect (URL Redirection to Untrusted Site) vulnerability in the CRM Perks WP Gravity Forms FreshDesk Plugin (gf-freshdesk) for WordPress. It affects all versions of the plugin from n/a through 1.3.5 and can be leveraged for phishing attacks. The vulnerability was published on December 9, 2025, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 4.3 (Medium) (Feedly, EUVD).

Technical details

The vulnerability is classified as CWE-601 (URL Redirection to Untrusted Site / 'Open Redirect'). It arises when the plugin fails to properly validate or sanitize user-supplied URL parameters before redirecting users, allowing an attacker to craft a malicious link that redirects victims to an arbitrary external site. Exploitation requires user interaction (e.g., a victim clicking a crafted link) and no authentication or elevated privileges are needed. The attack vector is network-based with low complexity (Feedly).

Impact

Successful exploitation enables phishing attacks by redirecting unsuspecting users from a trusted WordPress site to an attacker-controlled domain, potentially leading to credential harvesting or malware delivery. The confidentiality impact is rated low, with no direct integrity or availability impact on the server itself. The primary risk is reputational damage to the affected WordPress site and harm to end users who follow the malicious redirect (Feedly).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported for CVE-2025-67587. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033%, indicating a very low probability of exploitation in the near term (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Gravity Forms FreshDesk Plugin (gf-freshdesk) version 1.3.5 or earlier, using tools like WPScan or Google dorks.
  2. Craft malicious URL: Construct a URL targeting the vulnerable redirect parameter on the affected WordPress site, appending an attacker-controlled destination (e.g., https://victim-site.com/wp-content/plugins/gf-freshdesk/[vulnerable-endpoint]?redirect=https://attacker.com).
  3. Deliver phishing link: Send the crafted URL to target users via email, social media, or other channels, leveraging the trusted domain of the victim site to increase click-through rates.
  4. Harvest credentials or deliver malware: When the victim clicks the link, they are transparently redirected to the attacker's site, which may mimic a login page or serve malicious content.

Mitigation and workarounds

Users should update the WP Gravity Forms FreshDesk Plugin to a version beyond 1.3.5 if a patched release is available from CRM Perks. If no patch is yet available, administrators should consider deactivating the plugin until a fix is released. Additionally, web application firewalls (WAFs) can be configured to block or flag requests containing suspicious redirect parameters pointing to external domains (Feedly).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management