WordPress users are wary – this popular plugin has been diverted to push potential malware


  • The RocketGenus website served a malicious variant of the WordPress Forms supplement from Gravity for two days
  • The variant has collected extensive and authorized information for RCE
  • Malware only affected manual downloads and composer installations

Gravity Forms, a popular WordPress supplement with at least one million users, has been the victim of a supply chain attack in which threat actors tried to deploy malware to its users and resume their websites.

Patchstack safety researchers have discovered that someone has managed to infiltrate the Gravity Forms website and compromise the accommodated plug-in installation file.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top