The Gravity Forms WordPress Plugin Supply Chain Attack
Updated 5 Oct 2026 · Incident date 9 Jul 2025 · other
Gravity Forms 2.9.11.1 and 2.9.12 manual installers from gravityforms.com; fixed in 2.9.13common.phpIn July 2025, attackers changed the Gravity Forms plugin files on the official gravityforms.com download page. Versions 2.9.11.1 and 2.9.12 carried a backdoor. The fixed version is 2.9.13.
Only manual downloads and Composer installs were affected. Auto-updates and the Gravity API service were not compromised, according to SecurityWeek.
What happened
Attackers added malicious code to the plugin package that the official site served. Patchstack reports that the attacker registered the domain gravityapi.org on 8 July 2025. People downloaded the bad plugin on 9 and 10 July. Patchstack received reports on 11 July, and RocketGenius released 2.9.13 the same day.
Patchstack found the code in gravityforms/common.php and includes/settings/class-settings.php. It ran whenever the plugin was active, and it did two things:
- It sent site data to the attacker. This included the site URL, WordPress and PHP versions, active plugins and user count.
- It downloaded a Base64-encoded PHP file and wrote it to disk. BleepingComputer names
wp-includes/bookmark-canonical.php. Patchstack also listswp-includes/block-caching.php.
A second backdoor accepted requests with a secret token. With it, an attacker can create administrator accounts, run PHP code, upload files and list or delete users. BleepingComputer adds that the code blocked update attempts.
Patchstack states that the infection did not seem widespread. BleepingComputer and SecurityWeek put the plugin at about one million sites in total. Only sites that took the bad packages in the window were exposed.
Vigilance compares the version you trust with the new one. It reports the file that gained a new capability. A plugin that starts calling an outside domain is the kind of change it shows. See the scan block below.
Affected versions
- Gravity Forms 2.9.11.1 and 2.9.12, downloaded manually from gravityforms.com on 9 and 10 July 2025.
- Composer installs made from the official site during the same window. BleepingComputer states that a Composer install of 2.9.11 on 10 to 11 July was affected. SecurityWeek says 2.9.11.1.
- Fixed in 2.9.13.
Installs from the WordPress.org repository were not affected, according to Patchstack.
Indicators of compromise
- Domains:
gravityapi.organdgravityapi.io. - IP addresses:
185.193.89.19and193.160.101.6. - Files:
wp-includes/bookmark-canonical.phpandwp-includes/block-caching.php. - A reference to
gravityapi.orgingravityforms/common.php. - A
list_sectionsfunction inincludes/settings/class-settings.php. - Administrator accounts that nobody on your team created.
How to check
Search the plugin folder and wp-includes for the domain and the dropped files. Run this in the WordPress root.
grep -rIl "gravityapi" wp-content/plugins/gravityforms; ls -l wp-includes/bookmark-canonical.php wp-includes/block-caching.php
Then check the version with WP-CLI.
wp plugin get gravityforms --field=version
A version of 2.9.13 or later does not prove a clean site. A site that ran a bad version can still hold the dropped file. Also list administrator accounts with wp user list --role=administrator.
What to do now
- Update Gravity Forms to 2.9.13 or later from a trusted source.
- Delete the dropped files in
wp-includesif they exist. - Remove administrator accounts that you do not recognize.
- Change all administrator, database and hosting passwords. Rotate the WordPress salts.
- Block the domains and IP addresses above.
- If you find the backdoor, restore the site from a backup made before 9 July 2025 or rebuild it.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 64 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED common.php It now downloads from the internet, runs other programs and runs a hidden, encoded command. It did not before.
Frequently asked questions
Which Gravity Forms versions were compromised?
Versions 2.9.11.1 and 2.9.12 from the official gravityforms.com download page were compromised in July 2025. Version 2.9.13 removed the malicious code.
Did the Gravity Forms attack affect automatic updates?
No. SecurityWeek reports that the auto-update mechanism and the Gravity API service were not compromised. Only manual downloads and Composer installs were affected.
Sources
More supply chain attacks
- Linux Mint backdoored ISO 20 Feb 2016
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.