Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Inject Malware Into Gravity Forms WordPress Plugin 

Hackers Inject Malware Into Gravity Forms WordPress Plugin 

Posted on July 14, 2025July 14, 2025 By CWS

Two trojanized variations of the Gravity Varieties WordPress plugin have been distributed by way of the official obtain web page following a provide chain assault.

Gravity Varieties is an easy-to-use WordPress types builder that has over 1 million energetic installations. It gives a visible kind editor, helps transaction administration and workflow automation, and offers help for a broad vary of kind customizations.

The malicious exercise associated to Gravity Varieties was flagged on July 11, after Patchstack obtained a report that the plugin made an HTTP request to a suspicious area that was created on July 8.

The plugin was caught sending WordPress set up info within the request, and containing malicious capabilities that might be known as by unauthenticated customers to execute arbitrary code remotely on the server.

On the identical day, Gravity Varieties’ developer RocketGenius confirmed that malicious iterations of the plugin have been listed on the official obtain web page.

“For a restricted time and solely through particular strategies, two Gravity Varieties core plugin packages supplied for handbook obtain have been compromised by an exterior agent who made unauthorized code modifications,” the developer mentioned.

In line with RocketGenius, solely Gravity Varieties variations 2.9.11.1 and a couple of.9.12 obtainable by way of the obtain web page on July 9 and July 10 have been contaminated, albeit customers who ran a composer set up and put in 2.9.11.1 in the course of the timeframe additionally executed the malicious iteration.

The packages fetched through the auto-update mechanism weren’t malicious, nor was the Gravity API service that handles computerized updates, licensing, and installations compromised, the developer notes.Commercial. Scroll to proceed studying.

The malicious code within the compromised plugin variations, RocketGenius says, was designed to create an administrative account to the WordPress web site, making a backdoor and permitting attackers to entry the location set up remotely, execute code, manipulate accounts, and steal knowledge.

Model 2.9.13 of the plugin was launched on July 11 to take away the malicious code and customers are urged to replace as quickly as doable, particularly in the event that they manually downloaded a backdoored iteration on July 9 or July 10.

“All keys and credentials for all of the companies we use to retailer downloadable packages have been up to date to shut the potential for unauthorized entry. All administrative accounts have been audited and have had their passwords cycled,” RocketGenius notes.

Associated: Forminator WordPress Plugin Vulnerability Exposes 400,000 Web sites to Takeover

Associated: Vulnerability in OttoKit WordPress Plugin Exploited within the Wild

Associated: Menace Actors Deploy WordPress Malware in ‘mu-plugins’ Listing

Associated: Vital Plugin Flaw Uncovered 4 Million WordPress Web sites to Takeover

Security Week News Tags:Forms, Gravity, Hackers, Inject, Malware, Plugin, WordPress

Post navigation

Previous Post: Hackers Allegedly Selling WinRAR 0-day Exploit on Dark Web Forums for $80,000
Next Post: Hackers Weaponize Compiled HTML Help to Deliver Malicious Payload

Related Posts

Fortinet, Ivanti Release August 2025 Security Patches Fortinet, Ivanti Release August 2025 Security Patches Security Week News
TransUnion Data Breach Impacts 4.4 Million TransUnion Data Breach Impacts 4.4 Million Security Week News
Advanced Phishing Toolkit Resists Password Changes Advanced Phishing Toolkit Resists Password Changes Security Week News
In Other News: Critical Zoom Flaw, City’s Water Threatened by Hack, 0 Billion OT Cyber Risk In Other News: Critical Zoom Flaw, City’s Water Threatened by Hack, $330 Billion OT Cyber Risk Security Week News
Fencing and Pet Company Jewett-Cameron Hit by Ransomware Fencing and Pet Company Jewett-Cameron Hit by Ransomware Security Week News
ClickFix Attack Exploits Fake Cloudflare Turnstile to Deliver Malware ClickFix Attack Exploits Fake Cloudflare Turnstile to Deliver Malware Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark