Two infected versions of the Gravity Forms for WordPress were distributed via the official download page, following a supply chain.
See also: Critical vulnerability in WordPress plugin exposes over 600,000 sites

Gravity Forms is an easy-to-use form builder for WordPress, with over 1 million active installations. It offers a visual form editor, supports transaction management and workflow automation , and provides extensive form customization capabilities
The malicious activity related to Gravity Forms was detected on July 11th, after Patchstack received a report that the plugin was making an HTTP request to a suspicious domain that had been created on July 8th.
The plugin was found to be sending information about the WordPress installation and containing malicious functions that could be called by unauthorized users to remotely execute arbitrary code on the server.
On the same day, RocketGenius , the company that created Gravity Forms, confirmed that malicious versions of the plugin had been uploaded to the official download page.
See also: Over 100,000 WordPress sites at risk from plugin
According to RocketGenius, only versions 2.9.11.1 and 2.9.12 that were available via the download page on July 9 and 10 were infected. However, users who installed via composer and installed version 2.9.11.1 during the same time period also ran the malicious variant.

As the developer notes, the packages downloaded through the automatic update mechanism were not malicious, nor was the Gravity API, which manages automatic updates, licenses, and installations, affected.
The malicious code in the infected versions of the plugin, according to RocketGenius, was designed to create an administrator account on the WordPress site, thus opening a “backdoor” and allowing attackers to remotely access the installation, execute code, modify accounts, and steal data.
Version 2.9.13 of the add-on was released on July 11 to remove the malicious code, and users are urged to install it as soon as possible, especially if they manually downloaded an infected version on July 9 or 10.
See also: WordPress 'Motors' theme: Vulnerable to critical vulnerability
This incident is a reminder that even popular and trusted plugins are not immune to attacks and that WordPress security requires ongoing active management and attention
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
