WordPress users beware – this popular plugin has been hijacked to push potential malware




  • The RocketGenius website served a malicious variant of the Gravity Forms WordPress add-on for two days
  • The variant harvested extensive information and allowed for RCE
  • The malware affected only manual downloads and composer installations

Gravity Forms, a popular WordPress add-on with at least a million users, was victim of a supply chain attack in which threat actors tried to deploy malware to its users and take over their websites.

Security researchers from PatchStack discovered someone managed to infiltrate Gravity Forms’ website, and compromise the plug-in installation file hosted there.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *