Be careful with WordPress users: This popular complement has been kidnapped to boost possible malware




  • The Rocketgenius website served a malicious variant of the Gravity Forms WordPress complement for two days
  • The variant reaped extensive information and allowed RCE
  • Malware only affected manual downloads and composer facilities

Gravity Forms, a popular WordPress complement with at least one million users, was the victim of a supply chain attack in which the threat actors tried to implement malware to their users and take care of their websites.

Patchstack security researchers discovered that someone managed to infiltrate the Gravity Forms website and compromise the complement installation file lodged there.

Leave a Comment

Your email address will not be published. Required fields are marked *