HomeSecurityHackers inject malware into Gravity Forms WordPress plugin

Hackers inject malware into Gravity Forms WordPress plugin

Two infected versions of the Gravity Forms for WordPress were distributed via the official download page, following a supply chain.

See also: Critical vulnerability in WordPress plugin exposes over 600,000 sites

Gravity Forms WordPress

Gravity Forms is an easy-to-use form builder for WordPress, with over 1 million active installations. It offers a visual form editor, supports transaction management and workflow automation , and provides extensive form customization capabilities

The malicious activity related to Gravity Forms was detected on July 11th, after Patchstack received a report that the plugin was making an HTTP request to a suspicious domain that had been created on July 8th.

The plugin was found to be sending information about the WordPress installation and containing malicious functions that could be called by unauthorized users to remotely execute arbitrary code on the server.

On the same day, RocketGenius , the company that created Gravity Forms, confirmed that malicious versions of the plugin had been uploaded to the official download page.

See also: Over 100,000 WordPress sites at risk from plugin

According to RocketGenius, only versions 2.9.11.1 and 2.9.12 that were available via the download page on July 9 and 10 were infected. However, users who installed via composer and installed version 2.9.11.1 during the same time period also ran the malicious variant.

Hackers inject malware into Gravity Forms WordPress plugin
Hackers inject malware into Gravity Forms WordPress plugin

As the developer notes, the packages downloaded through the automatic update mechanism were not malicious, nor was the Gravity API, which manages automatic updates, licenses, and installations, affected.

The malicious code in the infected versions of the plugin, according to RocketGenius, was designed to create an administrator account on the WordPress site, thus opening a “backdoor” and allowing attackers to remotely access the installation, execute code, modify accounts, and steal data.

Version 2.9.13 of the add-on was released on July 11 to remove the malicious code, and users are urged to install it as soon as possible, especially if they manually downloaded an infected version on July 9 or 10.

See also: WordPress 'Motors' theme: Vulnerable to critical vulnerability

This incident is a reminder that even popular and trusted plugins are not immune to attacks and that WordPress security requires ongoing active management and attention

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS