Monday, 28 Jul 2025
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy
Nexpressdaily.com
  • Home
  • Politics
  • Finance
  • Health
  • Technology
  • Travel
  • World
  • 🔥
  • Technology
  • World
  • Finance
  • Politics
  • Travel
  • Health
Font ResizerAa
Nexpressdaily.comNexpressdaily.com
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Finance
  • Politics
  • Health
  • Technology
  • World
Search
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Categories
    • Finance
    • Politics
    • Technology
    • Travel
    • Health
    • World
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Technology

WordPress users beware – this popular plugin has been hijacked to push potential malware

Nexpressdaily
Last updated: July 16, 2025 12:05 pm
Nexpressdaily
Share
SHARE


  • The RocketGenius website served a malicious variant of the Gravity Forms WordPress add-on for a few hours
  • The variant harvested extensive information and allowed for RCE
  • The malware affected only manual downloads and composer installations

Gravity Forms, a popular WordPress add-on with at least a million users, was victim of a supply chain attack in which threat actors tried to deploy malware to its users and take over their websites.

Security researchers from PatchStack discovered someone managed to infiltrate Gravity Forms’ website, and compromise the plug-in installation file hosted there.

However, there are discrepancies in the timeline, and for how long the malware was being served.


You may like

According to Patchstack, on July 10 and 11, users could download Gravity Forms versions 2.9.11.1 and 2.9.12, which came with malicious files that collected extensive site metadata, and malware that allowed for remote code execution (RCE) attacks.

Carl Hancock, Gravity’s CEO and co-founder, told TechRadar Pro in a written statement that this was not true, and that the compromised .ZIP file was available only for a few hours.

“Patchstack’s timeline isn’t correct. The issue was sporadic beginning just before 8pm (EST or UTC-05:00) on the evening of July 9th and mitigated the morning of July 10th. There was then roughly a 1 hour window on the evening of July 10th where the attacker used a backup method they had in place to sloppily replace the download link on the downloads page once again. Our web host was then able to assist us in shutting the door for good on the method they were using to do this,” he said.

So, the July 10-11 timeframe is not correct – it was primarily overnight on July 9, with an additional one-hour window later on the 10th.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Risky manual downloads

The malware blocked any attempts to update the add-on, contacted an external server to deploy additional payloads, and created an admin account that granted attackers full control over the compromised website.

Gravity Forms is a premium WordPress plugin enabling users to build different forms using a drag-and-drop interface. It integrates with a wide range of third-party services, making it popular for contact forms, surveys, payment forms, and more.

RocketGenius, the company that develops Gravity Forms, determined that the malware affected only manual downloads and composer installations of the plugin.

“The Gravity API service that handles licensing, automatic updates, and the installation of add-ons initiated from within the Gravity Forms plugin was never compromised. All package updates managed through that service are unaffected,” RocketGenius explained.

The issue was confined to the gravityforms.com marketing and customer account site, Hancock further explained. This entity is not managed by the same web hosting company as Gravity’s licensing/automatic update/plugin installer/plugin repository API server that the plugin itself interacts with.

“The impact and exposure was minimal and we know the customers that were at risk of exposure and we’ve reached out to them on multiple occasions. Both during and after, as well as a follow up since then.”

The first clean version of the add-on is 2.9.13, which is now available for download.

Via BleepingComputer

Edit, July 16 – Added further clarification and a statement from Carl Hancock, Gravity Forms Co-Founder and CEO.

You might also like

Share This Article
Email Copy Link Print
Previous Article US ambassador Huckabee attends Netanyahu trial to show support from Trump
Next Article As Dominican Republic’s Fintech Sector Booms, Financial Inclusion Is Big Goal

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad imageAd image

Popular Posts

Death Stranding 2 is bigger and more ambitious — and that includes its music

Death Stranding 2: On the Beach is an expansive, captivating sequel filled with huge environments…

By Nexpressdaily

Israel-Gaza war live: plan to airdrop aid to Gaza ‘inefficient and a distraction’ with starvation deepening, UN says | Israel-Gaza war

Airdrops of aid to Gaza 'inefficient' and a 'distraction', UN saysThe head of the UN…

By Nexpressdaily

Qatar denies its offer of $400mn jet to Donald Trump is bribery

Unlock the White House Watch newsletter for freeYour guide to what Trump’s second term means…

By Nexpressdaily

You Might Also Like

Technology

Drive Capital’s second act –  how the Columbus venture firm found success after a split

By Nexpressdaily
Technology

The unbearable obviousness of AI fitness summaries

By Nexpressdaily
Technology

Mistral releases a vibe coding client, Mistral Code

By Nexpressdaily
Technology

Tesla’s Autopilot is under scrutiny in a rare jury trial

By Nexpressdaily
Nexpressdaily.com
Facebook Twitter Youtube Rss Medium

About US

NexpressDaily.com is a leading digital news platform committed to delivering timely, accurate, and unbiased news from around the world. From politics and business to technology, sports, health, and entertainment – we cover the stories that matter most. Stay connected with real-time updates, expert insights, and trusted journalism, all in one place.

Top Categories
  • World
  • Finance
  • Politics
  • Tech
  • Health
  • Travel
Usefull Links
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy

© Nexpressdaily. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?