WordPress -Users Take care – this popular plugin has been hijacked to push to potential malware


  • The RocketGenius site served a malicious variant of gravity forms the WordPress gain for two days
  • The variant harvested extensive information and enabled RCE
  • Malware affected only manual downloads and composer installations

Gravity Forms, a popular WordPress addition with at least one million users, fell victim to a supply chain attack in which threat actors tried to implement malware to their users and take over their websites.

Patchstack security researchers discovered that someone managed to infiltrate Gravity Forms’ website and compromise the plug-in installation file that is there.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top