Crmperks develops a suite of WordPress form-builder plugins and integrations designed to capture, manage, and route contact-form data to CRM platforms such as Zoho. Despite the narrow product focus, these plugins occupy a prominent position in the WordPress ecosystem due to their wide adoption across small-business and enterprise sites. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit tooling; the exposure centers on recurring weakness classes including cross-site scripting, unsafe deserialization, open redirects, SQL injection, and unrestricted file upload—all characteristic of PHP web-application handling of untrusted user input and form submissions. Defenders deploying these plugins should treat security updates as urgent and restrict administrative access; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Crmperks over time
Signals from CVEs in this vendor scope (41 CVEs).
41 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25080MEDIUM The Contact Form Entries WordPress plugin before 1.1.7 does not validate, sanitise and escape the IP address retrieved via headers such as CLIENT-IP and X-FORWARDED-FOR, allowing u | Jan 24, 2022 | 6.1 | 67 | NO | NO |
CVE-2024-30498CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks CRM Perks Forms.This issue affects CRM Perks Forms: from n/a through | Mar 29, 2024 | 10.0 | 39 | NO | YES |
CVE-2025-7384CRITICAL The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization | Aug 13, 2025 | 9.8 | 35 | NO | NO |
CVE-2025-60178CRITICAL Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms HubSpot gf-hubspot allows Object Injection.This issue affects WP Gravity Forms HubSpot: from n/a throu | Dec 18, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-60090CRITICAL Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms Insightly gf-insightly allows Object Injection.This issue affects WP Gravity Forms Insightly: from n/a | Dec 18, 2025 | 9.8 | 34 | NO | NO |
CVE-2021-25079MEDIUM The Contact Form Entries WordPress plugin before 1.2.4 does not sanitise and escape various parameters, such as form_id, status, end_date, order, orderby and search before outputti | Jan 24, 2022 | 6.1 | 34 | NO | YES |
CVE-2026-9843HIGH The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page fu | Jun 20, 2026 | 8.1 | 33 | NO | NO |
CVE-2026-2599CRITICAL The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization | Mar 5, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-60089CRITICAL Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Object Injection.This issue affects WP Gravity Forms FreshDesk Pl | Dec 18, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-57421HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks CRM Perks Forms crm-perks-forms allows Reflected XSS.This issue affe | Jul 13, 2026 | 7.1 | 31 | NO | NO |
Signals from CVEs in this vendor scope (41 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Crmperks.
Media articles that mention a CVE ID that affects a product developed by Crmperks — matched by CVE ID, not by vendor name.