Friday, August 21, 2026

Hackers Compromise WordPress GravityForms Plugin with Malicious Code Injection

Hackers have targeted the popular WordPress plugin Gravity Forms, injecting malicious code into versions downloaded from the official gravityforms.com domain.

The breach was first reported on July 11, 2025, when security researchers noticed suspicious HTTP requests to the domain gravityapi.org, which was registered just days earlier on July 8, 2025.

This domain, now suspended by registrar Namecheap, served as a command-and-control server for the malware.

Attack Details

The compromised plugin, specifically version 2.9.12, included backdoors that exfiltrated sensitive site data such as URLs, WordPress versions, PHP details, active plugins, and user counts, sending them via POST requests to the malicious endpoint.

Upon receiving a response, the code would decode and write a backdoored file, like wp-includes/bookmark-canonical.php, to the server, masquerading as legitimate WordPress content management tools.

This file contained remote code execution capabilities through eval functions triggered by unauthenticated requests, allowing attackers to manipulate posts, media, widgets, and themes with devastating effects.

The malware’s ingenuity lies in its integration with Gravity Forms’ core functions. For instance, the update_entry_detail function in gravityforms/common.php is hooked into the plugins_loaded action, ensuring it runs whenever the plugin is active.

It collects comprehensive site intelligence and, based on the server’s response, deploys additional payloads.

Another vector, the list_sections function in includes/settings/class-settings.php, accessible via notification.php, requires a specific gf_api_token (Cx3VGSwAHkB9yzIL9Qi48IFHwKm4sQ6Te5odNtBYu6Asb9JX06KYAWmrfPtG1eP3) and enables actions like creating admin users, executing arbitrary code via base64-decoded formulas, uploading files, listing or deleting users, and even browsing server directories.

This multifunctional backdoor turns infected sites into fully controllable assets for attackers.

Interestingly, the infection appears limited, as scans by major hosting providers indicate it wasn’t widespread, likely due to the brief availability of the tainted downloads only affecting manual and Composer installations, according to RocketGenius staff.

Mitigation Efforts

Swift action followed the discovery. By July 11, 2025, at 12:07 UTC, Gravity Forms confirmed an investigation into the malware breach, removing the malicious code from subsequent downloads.

Updates continued rapidly: at 12:38 UTC, Patchstack obtained vulnerable and patched versions, confirming the issue was isolated. By 14:10 UTC, version 2.9.13 was released as a safe update, and gravityapi.org was taken offline to prevent further exploitation.

This incident echoes a similar attack on the Groundhogg plugin, highlighting a pattern of targeted supply chain compromises in the WordPress ecosystem.

According to the Report, Security teams like Patchstack have been monitoring these threats, emphasizing the need for vigilance in plugin management.

For site owners, immediate steps are crucial: check for the presence of suspicious files or functions, update to 2.9.13, and scan for indicators like unexpected requests from IP addresses such as 193.160.101.6, which spoofed user agents to ping backdoor endpoints across sites.

While the attack’s scope seems contained, it underscores the risks of third-party plugins and the importance of secure download practices.

Engaging with this evolving threat not only protects individual sites but strengthens the broader WordPress community against sophisticated cyber adversaries.

Indicators of Compromise (IOCs)

CategoryIOC Details
IP Addresses185.193.89.19, 193.160.101.6
Domainsgravityapi.org, gravityapi.io
Files/Pathsgravityforms/common.php, includes/settings/class-settings.php, wp-includes/bookmark-canonical.php, wp-includes/block-caching.php, /wp-content/plugins/gravityforms_2.9.12/notification.php, /wp-content/plugins/gravityforms_2.9.11.1/notification.php, /wp-content/plugins/gravityforms/notification.php
Strings/Functionsgravityapi.org, update_entry_detail, list_sections, Cx3VGSwAHkB9yzIL9Qi48IFHwKm4sQ6Te5odNtBYu6Asb9JX06KYAWmrfPtG1eP3

Stay Updated on Daily Cybersecurity News. Follow us on Google News, LinkedIn, and X.

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts

Investment fraud is increasingly exploiting the one action banks...

UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft

A Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable...

Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access

Cybersecurity researchers have revealed a critical vulnerability in N-able’s...

OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing

OpenAI has reaffirmed its commitment to Zero Data Retention...

Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords

A business email compromise campaign is using emoji-filled JScript...

Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing

Quarkslab has argued that LLM-assisted reverse engineering does not...

Related Articles

Recent News