Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»WordPress Gravity Forms Developer hacked to push backdoor plugins
    Security

    WordPress Gravity Forms Developer hacked to push backdoor plugins

    PineapplesUpdateBy PineapplesUpdateJuly 12, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    WordPress Gravity Forms Developer hacked to push backdoor plugins
    Share
    Facebook Twitter LinkedIn Pinterest Email

    WordPress Gravity Forms Developer hacked to push backdoor plugins

    The popular WordPress plugin gravitational forms have been compromised in a supply-chain attack, where the manual installers of the official website were infected with a back door.

    Gravity form is a premium plugin for contact, payment and other online forms. Based on the vendor’s statistical data, the product is not placed on approximately one million websites, some belong to famous organizations such as AirbnB, NIKE, ESPN, Unicef, Google and Yale.

    Remote code execution on server

    WordPress Security firm Patchstack says it received a report today, which is about the suspected requests generated by plugins downloaded from the website gravitationally.

    After checking the plugin, the patchstack confirmed that it received a malicious file downloaded from the seller’s website (Gravityforms/Common.php). The closure examination revealed that the file began a post request for a suspected domain on “gravityapi.org/sites”.

    On further analysis, researchers found that the plugin collected a broad site metadata, including URL, administrator paths, themes, plugins and PHP/WordPress versions, and exfiltrate it to the attackers.

    The server reaction includes the Base64-encoded PHP malware, which is saved as “WP-Includes/Bookmark-Canonical.Php”.

    WordPress is meskcred by malware in the form of content management tools that enables remote code execution without the need to certify using ‘handle_posts (), “handle_media (),” handle_widgots () “.’

    “All those tasks can be said by __construct -> Init_CONTENT_MANAGEMENT -> Handles_Rex -> Process_Rec there. Therefore, it can basically be triggered by an uncontrolled user,” Patchstack tells,

    “From all tasks, it will make an eval call with the input supplied by the user, resulting in a distance code execution on the server,” the researchers said.

    The developer, behind the gravitational forms, was conveyed to the rocketgenius, and a staff member told the patchstack that Malware only impressed the manual download and plugin musician installation.

    Patchstack recommends that anyone who downloads the gravitational forms starting tomorrow restores the plugin by receiving a clean version. Admins should also scan their websites for any signal of infection.

    According to the patchstack, the domains that facilitated this operation were registered on 8 July.

    Hackers add admin accounts

    Rocktgenius has published a post -mortem of the incident that confirmed that only gravitational form 2.9.11.1 and 2.9.12 were available for manual downloads between 10 July to 11 July.

    If the admins installed a musician for version 2.9.11 on any of the two dates, they found an infected copy of the product.

    “Gravity API service that handles the installation of ad -on -on -on -on -on -on -on -on -on -on -on -on -on -on -on -on -Aon, was never compromised. All the package updates managed through that service are unaffected” – Rocketgenius

    Rocketgenius says that malicious code blocked updated efforts, contacted an external server to bring additional payload, and a administrator account added to the attacker gave full control of the website to the attacker.

    The developer also provides ways for administrators Check for potential infection By following the specific link on their websites.


    Tines needle

    While cloud attacks can be more sophisticated, the attackers still succeed with surprisingly simple techniques.

    Drawing by the detection of Vij in thousands of organizations, this report reveals the 8 major techniques used by Claude-Floid danger actors.

    backdoor developer Forms Gravity hacked plugins push WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThis large -scale AT and T data brech settlement can pay $ 5K to something: Find out if you are eligible
    Next Article Meta Quest 4 Rumors: Everything we know till now
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    I ‘hacked’ my home with 7 smart plug tips – here’s the setup (and why it works)

    November 10, 2025
    AI/ML

    AI training benchmarks push hardware limits

    October 31, 2025
    AI/ML

    Scientists must push AI toward responsible AI

    October 29, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Google tests AI-operated audio overview in search results for some questions

    June 16, 20250 Views

    Yes, this was the original voice of the Garat in the trailer for the thief VR

    June 16, 20250 Views

    Best LC10 loadout in call of duty: Warzone

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.