Monday, 28 Jul 2025
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy
Nexpressdaily.com
  • Home
  • Politics
  • Finance
  • Health
  • Technology
  • Travel
  • World
  • 🔥
  • Technology
  • World
  • Finance
  • Politics
  • Travel
  • Health
Font ResizerAa
Nexpressdaily.comNexpressdaily.com
  • My Saves
  • My Interests
  • My Feed
  • History
  • Travel
  • Finance
  • Politics
  • Health
  • Technology
  • World
Search
  • Pages
    • Home
    • Blog Index
    • Contact Us
    • Search Page
    • 404 Page
  • Personalized
    • My Feed
    • My Saves
    • My Interests
    • History
  • Categories
    • Finance
    • Politics
    • Technology
    • Travel
    • Health
    • World
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Technology

WordPress users beware – this popular plugin has been hijacked to push potential malware

Nexpressdaily
Last updated: July 16, 2025 12:05 pm
Nexpressdaily
Share
SHARE


  • The RocketGenius website served a malicious variant of the Gravity Forms WordPress add-on for a few hours
  • The variant harvested extensive information and allowed for RCE
  • The malware affected only manual downloads and composer installations

Gravity Forms, a popular WordPress add-on with at least a million users, was victim of a supply chain attack in which threat actors tried to deploy malware to its users and take over their websites.

Security researchers from PatchStack discovered someone managed to infiltrate Gravity Forms’ website, and compromise the plug-in installation file hosted there.

However, there are discrepancies in the timeline, and for how long the malware was being served.


You may like

According to Patchstack, on July 10 and 11, users could download Gravity Forms versions 2.9.11.1 and 2.9.12, which came with malicious files that collected extensive site metadata, and malware that allowed for remote code execution (RCE) attacks.

Carl Hancock, Gravity’s CEO and co-founder, told TechRadar Pro in a written statement that this was not true, and that the compromised .ZIP file was available only for a few hours.

“Patchstack’s timeline isn’t correct. The issue was sporadic beginning just before 8pm (EST or UTC-05:00) on the evening of July 9th and mitigated the morning of July 10th. There was then roughly a 1 hour window on the evening of July 10th where the attacker used a backup method they had in place to sloppily replace the download link on the downloads page once again. Our web host was then able to assist us in shutting the door for good on the method they were using to do this,” he said.

So, the July 10-11 timeframe is not correct – it was primarily overnight on July 9, with an additional one-hour window later on the 10th.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Risky manual downloads

The malware blocked any attempts to update the add-on, contacted an external server to deploy additional payloads, and created an admin account that granted attackers full control over the compromised website.

Gravity Forms is a premium WordPress plugin enabling users to build different forms using a drag-and-drop interface. It integrates with a wide range of third-party services, making it popular for contact forms, surveys, payment forms, and more.

RocketGenius, the company that develops Gravity Forms, determined that the malware affected only manual downloads and composer installations of the plugin.

“The Gravity API service that handles licensing, automatic updates, and the installation of add-ons initiated from within the Gravity Forms plugin was never compromised. All package updates managed through that service are unaffected,” RocketGenius explained.

The issue was confined to the gravityforms.com marketing and customer account site, Hancock further explained. This entity is not managed by the same web hosting company as Gravity’s licensing/automatic update/plugin installer/plugin repository API server that the plugin itself interacts with.

“The impact and exposure was minimal and we know the customers that were at risk of exposure and we’ve reached out to them on multiple occasions. Both during and after, as well as a follow up since then.”

The first clean version of the add-on is 2.9.13, which is now available for download.

Via BleepingComputer

Edit, July 16 – Added further clarification and a statement from Carl Hancock, Gravity Forms Co-Founder and CEO.

You might also like

Share This Article
Email Copy Link Print
Previous Article US ambassador Huckabee attends Netanyahu trial to show support from Trump
Next Article As Dominican Republic’s Fintech Sector Booms, Financial Inclusion Is Big Goal

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad imageAd image

Popular Posts

Federal Appeal Court grants pause of B.C. ostrich cull pending review

The Federal Court of Appeal has granted a stay that pauses the potential cull of…

By Nexpressdaily

‘A Beautiful Boost’: Lake Tahoe Reps Are Thrilled by Apple’s Reported New Mac OS Name

Apple's next Mac operating system is called macOS Tahoe, for Lake Tahoe, according to Bloomberg's Mark…

By Nexpressdaily

Fears of racial profiling over registration policy for immigrants in US illegally

PHOENIX -- The Trump administration's plan to strictly require anyone illegally in the U.S. to…

By Nexpressdaily

You Might Also Like

Technology

Miami-based Pelico, which offers a supply chain orchestration platform, raised a $40M Series B led by General Catalyst, bringing its total funding to $72M (Colin Campbell/Axios)

By Nexpressdaily
Technology

Some Gmail Users Now Will Get AI Email Summaries Automatically

By Nexpressdaily
Technology

The 12 best laptops for high school and college students

By Nexpressdaily
Technology

Get it now: NVIDIA releases Shield TV 9.2.1 update

By Nexpressdaily
Nexpressdaily.com
Facebook Twitter Youtube Rss Medium

About US

NexpressDaily.com is a leading digital news platform committed to delivering timely, accurate, and unbiased news from around the world. From politics and business to technology, sports, health, and entertainment – we cover the stories that matter most. Stay connected with real-time updates, expert insights, and trusted journalism, all in one place.

Top Categories
  • World
  • Finance
  • Politics
  • Tech
  • Health
  • Travel
Usefull Links
  • About us
  • Contact
  • History
  • My Interests
  • Privacy Policy

© Nexpressdaily. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?