๐Ÿ” CVE Alert

CVE-2025-58636

CRITICAL 9.8

WordPress WP Gravity Forms Keap/Infusionsoft Plugin <= 1.2.3 - Deserialization of untrusted data Vulnerability

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Object Injection.This issue affects WP Gravity Forms Keap/Infusionsoft: from n/a through <= 1.2.3.

CWE CWE-502
Vendor crm perks
Product wp gravity forms keap/infusionsoft
Published Nov 6, 2025
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for crm perks wp gravity forms keap/infusionsoft

Be the first to know when new critical vulnerabilities affecting crm perks wp gravity forms keap/infusionsoft are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

CRM Perks / WP Gravity Forms Keap/Infusionsoft
0 โ‰ค 1.2.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/gf-infusionsoft/vulnerability/wordpress-wp-gravity-forms-keap-infusionsoft-plugin-1-2-3-deserialization-of-untrusted-data-vulnerability?_s_id=cve

Credits

Phat RiO | Patchstack Bug Bounty Program