CVE-2025-60151
7.5CRM Perks · WP Gravity Forms HubSpot
An open redirect vulnerability in the WP Gravity Forms HubSpot plugin allows remote attackers to perform phishing attacks via crafted URLs.
Executive summary
A critical open redirect vulnerability in the CRM Perks WP Gravity Forms HubSpot plugin creates a significant risk for phishing campaigns targeting your users.
Vulnerability
This is an open redirect vulnerability (CWE-601) that occurs due to improper validation of user-supplied input in the plugin. The vulnerability is unauthenticated, allowing any remote attacker to redirect users to malicious third-party websites.
Business impact
The ability to perform open redirects is frequently leveraged in sophisticated phishing campaigns to deceive users into visiting malicious domains while appearing to originate from a trusted source. This can lead to credential theft, malware delivery, and significant reputational damage. With a CVSS score of 7.5, this vulnerability represents a high-risk vector that should be prioritized to maintain user trust and security.
Remediation
Immediate Action: Since no specific patch version is currently confirmed, administrators should immediately deactivate or remove the plugin until the vendor releases a security update.
Proactive Monitoring: Monitor web server access logs for anomalous redirect patterns or high volumes of traffic directed toward external domains originating from the plugin.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block or inspect URL parameters that perform external redirects, which may provide temporary protection.
Exploitation status
Public Exploit Available: No (exploit_available: unknown).
Analyst recommendation
Given the high CVSS score and the inherent danger of phishing attacks, organizations should treat this vulnerability with urgency. If the plugin is not mission-critical, remove it immediately to eliminate the exposure. If it must remain, implement strict egress filtering and WAF protections while awaiting an official vendor patch to remediate the underlying flaw.
More CRM Perks CVEs
Sources
Originally found and disclosed by Bonds | Patchstack Bug Bounty Program, per the CVE Program record.