Multiple CRM Perks plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'vx_debug' parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
WP Gravity Forms HubSpot
Affected versions: *-1.0.8
Patched versions: 1.0.9
Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
Affected versions: *-1.2.5
Patched versions: 1.2.6
WP Gravity Forms Constant Contact Plugin
Affected versions: *-1.0.5
Patched versions: 1.0.6
Database for Contact Form 7, WPforms, Elementor forms
Affected versions: *-1.2.1
Patched versions: 1.2.2
WP Gravity Forms Insightly
Affected versions: *-1.0.6
Patched versions: 1.0.7
Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
Affected versions: *-1.1.3
Patched versions: 1.1.4
WP Gravity Forms Dynamics CRM
Affected versions: *-1.0.7
Patched versions: 1.0.8
Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms
Affected versions: *-1.0.3
Patched versions: 1.0.4
Integration for HubSpot and WooCommerce
Affected versions: *-1.0.4
Patched versions: 1.0.5
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms
Affected versions: *-1.1.0
Patched versions: 1.1.1
WP Gravity Forms Zendesk
Affected versions: *-1.0.7
Patched versions: 1.0.8
CRM Perks Integration for Gravity Forms and Salesforce
Affected versions: *-1.2.5
Patched versions: 1.2.6
Integration for Gravity Forms and Pipedrive
Affected versions: *-1.0.6
Patched versions: 1.0.7
WP Gravity Forms Keap/Infusionsoft
Affected versions: *-1.1.4
Patched versions: 1.1.5
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
Affected versions: *-1.1.0
Patched versions: 1.1.1
WP Gravity Forms Zoho CRM and Bigin
Affected versions: *-1.1.5
Patched versions: 1.1.6
WP Gravity Forms FreshDesk Plugin
Affected versions: *-1.2.8
Patched versions: 1.2.9
Integration for WooCommerce and Salesforce
Affected versions: *-1.5.8
Patched versions: 1.5.9
WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
Affected versions: *-1.0.8
Patched versions: 1.0.9
Connector for Gravity Forms and Google Sheets
Affected versions: *-1.1.0
Patched versions: 1.1.1
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin
Affected versions: *-1.1.8
Patched versions: 1.1.9
Integration for WooCommerce and QuickBooks
Affected versions: *-1.1.8
Patched versions: 1.1.9
WP Keap/Infusionsoft WooCommerce Plugin
Affected versions: *-1.0.8
Patched versions: 1.0.9
Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin
Affected versions: *-1.2.3
Patched versions: 1.2.4
WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
Affected versions: *-1.0.7
Patched versions: 1.0.8
Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms
Affected versions: *-1.0.9
Patched versions: 1.1.0
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms
Affected versions: *-1.1.9
Patched versions: 1.2.0
Researcher credit: WPScanTeam
Applicable copyright and licence notices
This record contains material that is subject to copyright
Copyright 2012-2026 Defiant Inc.
Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.
Licence reference