WordPress users beware – this popular plugin has been hijacked to push potential malware
- The RocketGenius website served a malicious variant of the Gravity Forms WordPress add-on for two days
- The variant harvested extensive information and allowed for RCE
- The malware affected only manual downloads and composer installations
Gravity Forms, a popular WordPress add-on with at least a million users, was victim of a supply chain attack in which threat actors tried to deploy malware to its users and take over their websites.
Security researchers from PatchStack discovered someone managed to infiltrate Gravity Forms’ website, and compromise the plug-in installation file hosted there.
On July 10 and 11, users could download Gravity Forms versions 2.9.11.1 and 2.9.12, which came with malicious files that collected extensive site metadata, and malware that allowed for remote code execution (RCE) attacks.
Risky manual downloads
The malware also blocked any attempts to update the add-on, contacted an external server to deploy additional payloads, and created an admin account that granted attackers full control over the compromised website.
Gravity Forms is a premium WordPress plugin enabling users to build different forms using a drag-and-drop interface. It integrates with a wide range of third-party services, making it popular for contact forms, surveys, payment forms, and more.
After being notified about the attack, RocketGenius, the company that develops Gravity Forms, investigated further, and determined that the malware affected only manual downloads and composer installations of the plugin.
“The Gravity API service that handles licensing, automatic updates, and the installation of add-ons initiated from within the Gravity Forms plugin was never compromised. All package updates managed through that service are unaffected,” RocketGenius explained.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Therefore, all users who downloaded Gravity Forms directly from RocketGenius’ website on either July 10 or 11, should delete the plug-in and reinstall it with a clean version. Furthermore, admins should analyze their websites for any signs of compromise.
The first clean version of the add-on is 2.9.13, which is now available for download.
Via BleepingComputer
You might also like
The RocketGenius website served a malicious variant of the Gravity Forms WordPress add-on for two days The variant harvested extensive information and allowed for RCE The malware affected only manual downloads and composer installations Gravity Forms, a popular WordPress add-on with at least a million users, was victim of a…
Recent Posts
- Shokz upgraded its open earbuds with better sound and a lighter design
- Shokz says its clip-on OpenDots 2 earbuds focus on improved volume and bass
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- Nomad Goods Promo Codes: Get 25% Off in June 2026
- NordVPN Coupons and Deals: 77% Off in June 2026
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023